Fortinet white logo
Fortinet white logo

Configuring the vNetwork for the transparent modes

Configuring the vNetwork for the transparent modes

A simple Xen bridge configuration does not function with FortiWeb bridges (V-zones), which will be used if you deploy your FortiWeb-VM in either true transparent proxy or Transparent Inspection operation mode.

For information on how to choose the operation mode, see the setup instructions in the FortiWeb Administration Guide.

Use the following general configuration steps to support the transparent modes:

  • To create the bridge, use one of the following to create two FortiWeb ports: one for the web server side and one for the client side:
    • 2 vSwitches or distributed vSwitches (dvSwitch)
    • 1 vSwitch that has 2 port groups with different VLAN IDs
  • Set each vSwitch that you add to promiscuous mode and map each port group to a network adapter (vNIC) in the vNIC configuration (see Deploying via Virtual Machine Manager or Deploying via dom0 command line)

Similar to a deployment that does not use virtual machines, connections between clients and servers are piped through two port groups (on two vSwitches or a single vSwitch) that comprise the bridge, with FortiWeb-VM in between them.

For instructions on how to create distributed vSwitches, see:

http://wiki.xen.org/wiki/Xen_Networking#Open_vSwitch

Configuring the vNetwork for the transparent modes

Configuring the vNetwork for the transparent modes

A simple Xen bridge configuration does not function with FortiWeb bridges (V-zones), which will be used if you deploy your FortiWeb-VM in either true transparent proxy or Transparent Inspection operation mode.

For information on how to choose the operation mode, see the setup instructions in the FortiWeb Administration Guide.

Use the following general configuration steps to support the transparent modes:

  • To create the bridge, use one of the following to create two FortiWeb ports: one for the web server side and one for the client side:
    • 2 vSwitches or distributed vSwitches (dvSwitch)
    • 1 vSwitch that has 2 port groups with different VLAN IDs
  • Set each vSwitch that you add to promiscuous mode and map each port group to a network adapter (vNIC) in the vNIC configuration (see Deploying via Virtual Machine Manager or Deploying via dom0 command line)

Similar to a deployment that does not use virtual machines, connections between clients and servers are piped through two port groups (on two vSwitches or a single vSwitch) that comprise the bridge, with FortiWeb-VM in between them.

For instructions on how to create distributed vSwitches, see:

http://wiki.xen.org/wiki/Xen_Networking#Open_vSwitch