Link to home
Start Free TrialLog in
Avatar of Pyradia
PyradiaFlag for Canada

asked on

Fortigate 80c - Vlan setup

Hello,

I setup a new Cisco small business Wap200 with 2 SSID.  The first one for compagny activity on network 10.10.10.0 and the other is the guest  wireless Network on 10.10.12.0.  VLAN ID are 1 and 2.

I have no problem with the  VLAN 1 (compagny network) but I can not acces to Internet with the Vlan 2.  I can ping the router at 10.10.12.254 and I can manage the Fortigate 80c from this network.

So I created the Firewall adresses for the range 10.10.12.0/255.255.255.0 with names Vlan_2_net and created the policy like this:

Source Interface: Internal
Source Address:     Vlan_2_net
Destination Interface: Wan1
Destination Address:  all (the range is 0.0.0.0/0.0.0.0)
Schedule: Always
Service: Any
Action: accept
and NAT is enable

Still no access to Internet (google or pinging 209.85.175.105).  What I don't understand?
Thank you!
Avatar of jcparedes
jcparedes
Flag of Peru image

I'd recommed to create a virtual interface on the Fortigate and assign the ip address 10.10.12.254 to it. Then create a new firewall route that uses that interface as the source interface.

Or maybe you just need to change the source interface in your firewall rule.
ASKER CERTIFIED SOLUTION
Avatar of myramu
myramu

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Pyradia

ASKER

Thank you.  It's helpful.
Avatar of myramu
myramu

You are welcome.