Professional Documents
Culture Documents
Config Vlan Fortigate-2
Config Vlan Fortigate-2
Config Vlan Fortigate-2
Switch#conf t
Switch#conf t
Switch(config)#hostname 2960-RG
2960-RG(config)#no ip domain-name
2960-RG(config)#end
2960-RG(config)#no cdp
2960-RG(confie)# service password-encryption
2960-RG(config)#enable secret 12345
2960-RG(config)#line con 0
2960-RG(config)#password 6789
2960-RG(config)#login
2960-RG#conf t
2969-RG (config)#interface vlan 10
2969-RG (config-if)#ip adress 10.0.200.1 255.0.0.0
2969-RG (config)#ip default-gateway 10.0.4.1
2960-RG(config)#interface 0/24
2960-RG(config)#switchport trunk encapsulation dot1q
2960-RG(config-if)#switchport mode trunk
2960-RG(config)#interface f 0/24
2960-RG(config-if)#switchport trunk allowed vlan add 10,20,30,40 tagged
Configuration du fortigate
Les règles de Pare-feu 1, 2 ,3,4,5,6 pas besoin d’activer le NAT car les Vlan doivent
iniquement communiquer en interne , mais les règles de pare-feu 7,8,9 j’active le Nat
puisque les vlan 20,30 et 40 doivent communiquer avec l’extérieur.
edit 3
set srcintf VLAN_10
set srcaddr VLAN_10_Net
set dstintf VLAN_30
set dstaddr VLAN_30_Net
set schedule always
set service ALL
set action accept
set nat disable
set status enable
next
edit 4
set srcintf VLAN_30
set srcaddr VLAN_30_Net
set dstintf VLAN_10
set dstaddr VLAN_10_Net
set schedule always
set service ALL
set action accept
set nat disable
set status enable
next
edit 5
set srcintf VLAN_20
set srcaddr VLAN_20_Net
set dstintf VLAN_30
set dstaddr VLAN_30_Net
set schedule always
set service ALL
set action accept
set nat disable
set status enable
next
edit 6
set srcintf VLAN_30
set srcaddr VLAN_30_Net
set dstintf VLAN_20
set dstaddr VLAN_20_Net
set schedule always
set service ALL
set action accept
set nat disable
set status enable
next
edit 7
set srcintf VLAN_20
set srcaddr VLAN_20_Net
set dstintf external
set dstaddr all
set schedule always
set service ALL
set action accept
set nat enable
set status enable
next
edit 8
set srcintf VLAN_30
set srcaddr VLAN_30_Net
set dstintf external
set dstaddr all
set schedule always
set service ALL
set action accept
set nat enable
set status enable
end
edit 9
set srcintf VLAN_40
set srcaddr VLAN_40_Net
set dstintf external
set dstaddr all
set schedule always
set service ALL
set action accept
set nat enable
set status enable
end
Configuration du serveur dhcp sur le fortigate pour attribuer des adresses ip au vlan 30 et 40
next
edit 2
set dns-service default
set default-gateway 213.136.100.153 set netmask 255.255.255.0
set interface vlan_40
config ip-range
edit 2
set start-ip 10.0.5.2 set end-ip 10.0.5.254
End
Configuration un zone incluant une interface physique et des VLAN