Technical Tip: How to configure a FortiGate for a directly connected Layer-3 Switch handling VLANs and Inter-VLAN routing
| Description | This article describes an example configuration containing a downstream Layer-3 switch configured with VLANs and Inter-VLAN routing. When Inter-VLAN routing is done by a downstream Layer-3 switch, FortiGate is unfamiliar with the VLANs created on the downstream switch. |
| Scope | FortiOS, FortiGate, Routing, Inter-VLAN. |
| Solution |
Topology:
  Configuration: The following steps focus on the FortiGate configuration only.
Port2 on FortiGate:
  Static Route for each VLAN on FortiGate:  
  Firewall Policy:
    Verification: Once the above configuration is completed, downstream devices should have internet access. Packet capture on FortiGate should demonstrate the downstream VLAN traffic without VLAN tagging reaching FortiGate, destined for the internet. A VLAN tag 802.1Q header is not present in the capture, verifying that traffic is reaching FortiGate untagged.
Traffic Verification: User from VLAN behind the switch should be able to ping FortiGate LACP IP.
Use the below sniffer to verify traffic is hitting the FortiGate:
diagnose sniffer packet any ' host x.x.x.x ' 4 0 l , x.x.x.x is the DST ip user trying to reach
Related articles: |








