Skip to main content
snowman_FTNT
Staff
Staff
May 20, 2016

Technical Tip: Behaviour on the GUI of the Interface Role introduced in v5.4

  • May 20, 2016
  • 0 replies
  • 18263 views

Description

 
This article describes the new Interface Role option and how it affects the GUI options available when editing a network interface on the FortiGate.

FortiOS 5.4 introduced the concept of Interface Roles that can be assigned to a given Network Interface. Each interface can be defined as one of the following roles: LAN, WAN, DMZ, or Undefined. When these roles are set, they will hide/reveal parts of the configuration in the GUI based on what is appropriate for the role.

 

Scope

 

FortiOS 5.4 and later.


Solution

 
Role type:
 
  1. Undefined role: All options in GUI are shown and configurable unless noted otherwise.

  2. WAN role: This role is meant for interfaces that connect to the Internet.
    The interface is set to DHCP by default.
    Receive LLDP is set to Enable, and Transmit LLDP is set to Use VDOM Setting (FortiOS 6.2 and later).
    The following features and options are hidden: WAN role:
    • Device Identification.
    • One-arm sniffer (Addressing Mode).
    • Auto-Managed by IPAM (Addressing Mode).
    • Dedicate to extension/FortiAP modes.
    • DHCP server.
    • Security mode and Admission control.

  3. LAN role.
    • This role is meant for interfaces that are used for local networks and internal endpoints.
    • The 'Create address object matching subnet' option is shown and toggled on (FortiOS 6.2 and later for the LAN and DMZ roles).
    • This option creates an Interface Subnet object that is based on the subnet associated with the interface.
    • Receive LLDP is set to Use VDOM Setting, and Transmit LLDP is set to Enable (FortiOS 6.2 and later).
    • The following features and options are hidden:
      • Secondary IP address (in 5.4.0 only)
      • Estimated bandwidth.
     
  4. DMZ role.
    • This role is meant for interfaces that are hosting servers, especially those that are exposing services to the Internet (i.e. separating publicly reachable servers from the rest of the corporate network/LAN).
    • Receive LLDP and Transmit LLDP are both set to Use VDOM Setting (FortiOS 6.2 and later)
    • The following features and options are hidden:
      • Secondary IP address (5.4.0 only).
      • Estimated bandwidth.
      • DHCP server.
      • Admission Controls.

    The following screenshot is an example of the GUI where the interface is set with an undefined role where all options are configurable.

    jjuracka_FD38714_tn_FD38714-1.jpg
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.