Configure a Layer 2 interfaces with a VLAN for switching and traffic
separation.
Where Can I Use
This? | What Do I Need? |
When your organization wants to divide a LAN into separate virtual LANs
(VLANs) to keep traffic and policy rules for different departments separate, you can
logically group Layer 2 hosts into VLANs and thus divide a Layer 2 network segment
into broadcast domains. For example, you can create VLANs for the Finance and
Engineering departments.
The firewall acts as a switch to forward a frame with an
Ethernet header containing a VLAN ID, and the destination interface must have a
subinterface with that VLAN ID in order to receive that frame and forward it to the
host. You configure a Layer 2 interface on the firewall and configure one or more
logical subinterfaces for the interface, each with a VLAN tag (ID).