Skip to main content
Contributor III
March 4, 2005

Avoiding ARP problems with VLANs in Transparent mode

  • March 4, 2005
  • 0 replies
  • 6453 views

Article

Description

This article explains how to avoid problems with ARP packets passing between VLANs in Transparent mode.

Components

FortiGate units running FortiOS version 4.00 MR3 and 5.0.x

Information

One essential application of virtual domains (VDOMs) is to prevent problems caused when a FortiGate unit is connected to a layer-2 switch that has a global MAC table. FortiGate units normally forward ARP requests to all interfaces, including VLAN subinterfaces. It is then possible for the switch to receive duplicate ARP packets on different VLANs. Some layer-2 switches reset when this happens.

The solution is to use the forward-domain command. The forward-domain command was introduced in FortiOS v3.0 MR1 and it tags VLAN traffic as belonging to a particular forward-domain collision group, and only VLANs tagged as part of that collision group receive that traffic. By default ports and VLANs are part of forward-domain collision group 0. For more information, see the VDOM Admin chapter in the FortiGate CLI Reference and the FortiGate VLANs and VDOMs Guide.





Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!