Re: Create VLAN without specifying an IP address
2020/11/05 06:29:44
(permalink)
Hi Ken,
Thank you for your reply.
I don't want anything talking on the LAN, except some devices that I have identified. I don't want the fortinet equipment even consuming one of the precious IP addresses on the subnet. I want a guarantee that nothing else can transmit on the LAN -- I want routing disabled. I don't want the firewall to even have an opportunity to allow someone else to talk on this LAN, even if misconfigured. If the switch must have an IP address on the LAN, then I have no guarantee about any of this and instead have to trust my understanding of FortiNet, trust my configuration, and trust that there are no bugs in any of the FortiNet software, no hackers, etc.
In the old-old days we would use ethernet cables an an unmanaged switch to accomplish this. In more recent times we would create a "virtual LAN" (or "VLAN" for short) to accomplish this. Apparently this is impossible with the FortiNet setup?
Chris