Simple definition
Transparent Mode allows a FortiGate to filter traffic mainly as a Layer 2 bridge without becoming the primary IP gateway for the networks it crosses.
Technical definition
In this mode, participating interfaces forward frames between segments while applying configured firewall policies and inspection features. The FortiGate keeps dedicated management configuration, while the data path can be inserted without renumbering existing subnets.
How it works / role
A frame received on an interface is learned and forwarded according to the Layer 2 behavior of the transparent domain, then evaluated by the corresponding security policies. Host routing can remain unchanged because their IP gateways remain outside the FortiGate.
What is it used for?
Insert a firewall into an existing architecture to control and inspect traffic without immediately changing addressing or gateway design.
Practical example
A FortiGate is placed between an access switch and the existing router; it enforces security policies while endpoints keep their current default gateway.
Common issues
- The management address or access path is misconfigured
- A Layer 2 loop or unexpected forwarding behavior appears
- A required policy is missing although physical connectivity is correct
- Troubleshooting incorrectly assumes NAT/Route mode behavior
Related terms
Key takeaway: In transparent mode, troubleshoot it as a filtered Layer 2 path and check forwarding, policies, and management separately.