Skip to main content
ChrisStankevitz
New Member
November 4, 2020
Solved

Create VLAN without specifying an IP address

  • November 4, 2020
  • 1 reply
  • 13126 views

I want to create a VLAN.  I do not want to create a VLAN Interface.  I do not want routing/gateway capability.  I do not want the FortiSwitch/FortiGate to take an IP address on this VLAN.

 

Is this possible?  I'm beginning to think that in the FortiWorld it is impossible to create a Layer2-only entity.

 

Thank you,

 

Chris

    Best answer by brycemd

    Just leave the IP as default. 0.0.0.0/0.0.0.0

     

    Edit:

    I guess we should clarify if we are talking from the fortigate/managed fortiswitch perspective or from a standalone fortiswitch perspective.

     

    From a standalone fortiswitch perspective, you do not need to specifiy any IP for any VLAN, it doesn't even ask unless you are creating a management interface. Same as really any other switch out there.

     

    From a FortiGate/managed fortiswitch perspective you can set the IP to 0.0.0.0/0.0.0.0 to accomplish the same thing.

    1 reply

    emnoc
    New Member
    November 4, 2020

    No it's not possible in a std  L3 firewall configuration. You need a layer3 address. What are you trying to do specifically so we can understand this request?

     

     

    Ken Felix

    ChrisStankevitz
    New Member
    November 5, 2020

    Hi Ken,

     

    Thank you for your reply.

     

    I don't want anything talking on the LAN, except some devices that I have identified.  I don't want the fortinet equipment even consuming one of the precious IP addresses on the subnet.  I want a guarantee that nothing else can transmit on the LAN -- I want routing disabled.  I don't want the firewall to even have an opportunity to allow someone else to talk on this LAN, even if misconfigured.  If the switch must have an IP address on the LAN, then I have no guarantee about any of this and instead have to trust my understanding of FortiNet, trust my configuration, and trust that there are no bugs in any of the FortiNet software, no hackers, etc.

     

    In the old-old days we would use ethernet cables an an unmanaged switch to accomplish this.  In more recent times we would create a "virtual LAN" (or "VLAN" for short) to accomplish this.  Apparently this is impossible with the FortiNet setup?

     

    Chris

    brycemd
    brycemdAnswer
    New Member
    November 5, 2020

    Just leave the IP as default. 0.0.0.0/0.0.0.0

     

    Edit:

    I guess we should clarify if we are talking from the fortigate/managed fortiswitch perspective or from a standalone fortiswitch perspective.

     

    From a standalone fortiswitch perspective, you do not need to specifiy any IP for any VLAN, it doesn't even ask unless you are creating a management interface. Same as really any other switch out there.

     

    From a FortiGate/managed fortiswitch perspective you can set the IP to 0.0.0.0/0.0.0.0 to accomplish the same thing.