152
www.fortinet.com FortiGate VLANs and VDOMs Version 3.0 USER GUIDE

VLANs and VDOMs Guide - Firewall · PDF fileFortiGate VLANs and VDOMs Version 3.0 User Guide ... VLAN layer-3 routing ... Asymmetric routing

  • Upload
    lethuy

  • View
    244

  • Download
    2

Embed Size (px)

Citation preview

  • www.fortinet.com

    FortiGate VLANs and VDOMs Version 3.0

    U S E R G U I D E

  • FortiGate VLANs and VDOMs User GuideVersion 3.010 SEPTEMBER 200701-30005-0091-20070910

    Copyright 2007 Fortinet, Inc. All rights reserved. No part of this publication including text, examples, diagrams or illustrations may be reproduced, transmitted, or translated in any form or by any means, electronic, mechanical, manual, optical or otherwise, for any purpose, without prior written permission of Fortinet, Inc.

    TrademarksDynamic Threat Prevention System (DTPS), APSecure, FortiASIC, FortiBIOS, FortiBridge, FortiClient, FortiGate, FortiGate Unified Threat Management System, FortiGuard, FortiGuard-Antispam, FortiGuard-Antivirus, FortiGuard-Intrusion, FortiGuard-Web, FortiLog, FortiAnalyzer, FortiManager, Fortinet, FortiOS, FortiPartner, FortiProtect, FortiReporter, FortiResponse, FortiShield, FortiVoIP, and FortiWiFi are trademarks of Fortinet, Inc. in the United States and/or other countries. The names of actual companies and products mentioned herein may be the trademarks of their respective owners.

  • Contents

    ContentsIntroduction ........................................................................................ 7

    About FortiGate VLANs and VDOMs ............................................................... 7

    About this document......................................................................................... 7Document conventions.................................................................................. 7

    FortiGate documentation .................................................................................. 8

    Related documentation ..................................................................................... 9FortiManager documentation ........................................................................ 9FortiClient documentation ........................................................................... 10FortiMail documentation.............................................................................. 10FortiAnalyzer documentation ...................................................................... 10Fortinet Knowledge Center ......................................................................... 10Comments on Fortinet technical documentation......................................... 10

    Customer service and technical support ...................................................... 11

    Introduction to VLANs and VDOMs................................................ 13Overview of VLAN technology ....................................................................... 13

    VLAN layer-2 switching ............................................................................... 14VLAN layer-3 routing................................................................................... 16Rules for VLAN IDs ..................................................................................... 18

    Overview of Virtual Domains .......................................................................... 18Maximum number of VDOMs...................................................................... 18Inter-VDOM routing ..................................................................................... 19Management VDOM ................................................................................... 19Administration of virtual domains ................................................................ 19Global and virtual domain settings .............................................................. 20For more information................................................................................... 22

    Using VLANs in NAT/Route mode.................................................. 23Overview........................................................................................................... 23

    Configuring FortiGate units in NAT/Route mode ......................................... 23Adding VLAN subinterfaces ........................................................................ 24Creating firewall policies ............................................................................. 25Configuring routing...................................................................................... 25

    Example configuration NAT/Route mode (simple) ....................................... 26General configuration steps ........................................................................ 27Configuring the FortiGate-800 unit .............................................................. 27Configuring the Cisco switch to support VLAN tags.................................... 33Testing the configuration............................................................................. 34

    FortiGate VLANs and VDOMs Version 3.0 User Guide 01-30005-0091-20070910 3

  • 4

    Contents

    Example configuration NAT/Route mode (complex).................................... 35General configuration steps ........................................................................ 36Configuring the FortiGate-800 unit.............................................................. 37Configuring the FortiGate-800 IPSec VPN tunnel and encrypt policy......... 45Configuring the VPN client.......................................................................... 49Configuring the internal Cisco switch.......................................................... 51Configuring the external Cisco switch......................................................... 51Testing the configuration............................................................................. 52

    Using VDOMs in NAT/Route mode................................................. 55Overview........................................................................................................... 55

    Getting started with VDOMs........................................................................... 55Enabling virtual domain configuration ......................................................... 55Creating virtual domains ............................................................................. 56Creating administrators for virtual domains ................................................ 57Accessing virtual domains to configure them.............................................. 57

    Configuring virtual domains........................................................................... 59Changing the management VDOM............................................................. 59Adding interfaces and VLAN subinterfaces to a virtual domain .................. 60Configuring routing for a virtual domain ...................................................... 61Configuring firewall policies for a virtual domain......................................... 61Configuring VPNs for a virtual domain........................................................ 61

    Example VDOM configuration in NAT/Route mode (simple)....................... 62General configuration steps ........................................................................ 63Creating the virtual domains ....................................................................... 63Configuring the FortiGate-800 external and DMZ interfaces ...................... 64Configuring the ABCdomain VDOM............................................................ 65Configuring the DEFdomain VDOM............................................................ 69Configuring the Cisco switch....................................................................... 73Testing the configuration............................................................................. 73

    Example VDOM configuration in NAT/Route mode (complex).................... 75General configuration steps ........................................................................ 77Creating the virtual domains ....................................................................... 77Configuring the ABCdomain VDOM............................................................ 78Configuring the Commercial VDOM............................................................ 84Configuring the Cisco switch....................................................................... 94Testing the configuration............................................................................. 95

    Using VLANs and VDOMs in Transparent mode .......................... 97Overview........................................................................................................... 97

    VLANs and virtual domains......................................................................... 97

    Configuring the FortiGate unit in Transparent mode................................... 98Adding VLAN subinterfaces ........................................................................ 98Creating firewall policies ............................................................................. 99

    FortiGate VLANs and VDOMs Version 3.0 User Guide 01-30005-0091-20070910

  • Contents

    Example configuration Transparent mode (simple)................................... 100General configuration steps ...................................................................... 101Configuring the FortiGate-800 unit ............................................................ 101Configuring the Cisco switch..................................................................... 106Configuring the Cisco router ..................................................................... 106Testing the configuration........................................................................... 108

    Example configuration Transparent mode (multiple virtual domains)..... 109Configuring