System network
VLANs in NAT/Route mode
FortiGate-1000 Administration Guide
01-28006-0009-20041105
63
Figure 14: Basic VLAN topology
FortiGate units and VLANs
In a typical VLAN configuration, 802.1Q-compliant VLAN layer-2 switches or layer-3
routers or firewalls add VLAN tags to packets. Packets passing between devices in
the same VLAN can be handled by layer 2 switches. Packets passing between
devices in different VLANs must be handled by a layer 3 device such as router,
firewall, or layer 3 switch.
Using VLANs, a single FortiGate unit can provide security services and control
connections between multiple security domains. Traffic from each security domain is
given a different VLAN ID. The FortiGate unit can recognize VLAN IDs and apply
security policies to secure network and IPSec VPN traffic between security domains.
The FortiGate unit can also apply authentication, protection profiles, and other firewall
policy features for network and VPN traffic that is allowed to pass between security
domains.
VLANs in NAT/Route mode
Operating in NAT/Route mode, the FortiGate unit functions as a layer 3 device to
control the flow of packets between VLANs. The FortiGate unit can also remove VLAN
tags from incoming VLAN packets and forward untagged packets to other networks,
such as the Internet.
VLAN Switch or router
Internet
VLAN 1
VLAN 2
VLAN 1 network
VLAN 2 network
VLAN trunk
POWER
VLAN 1
VLAN 2
Firewall or
Router
Esc
Enter
Untagged
packets
Содержание FortiGate FortiGate-1000
Страница 46: ...46 01 28006 0009 20041105 Fortinet Inc Changing the FortiGate firmware System status...
Страница 72: ...72 01 28006 0009 20041105 Fortinet Inc FortiGate IPv6 support System network...
Страница 80: ...80 01 28006 0009 20041105 Fortinet Inc Dynamic IP System DHCP...
Страница 110: ...110 01 28006 0009 20041105 Fortinet Inc FortiManager System config...
Страница 116: ...116 01 28006 0009 20041105 Fortinet Inc Access profiles System administration...
Страница 246: ...246 01 28006 0009 20041105 Fortinet Inc CLI configuration Users and authentication...
Страница 322: ...322 01 28006 0009 20041105 Fortinet Inc CLI configuration Antivirus...
Страница 370: ...370 01 28006 0009 20041105 Fortinet Inc CLI configuration Log Report...
Страница 384: ...384 01 28006 0009 20041105 Fortinet Inc Glossary...
Страница 392: ...392 01 28006 0009 20041105 Fortinet Inc Index...