Skip to main content
leblanda
New Member
August 30, 2018
Question

DMZ and unused Wan port on switch not working

  • August 30, 2018
  • 2 replies
  • 4181 views

My setup

fortigate 60e

FortiOS v5.6.5 build1600 (GA)

 

I need more port in my network and need to be al on the same subnet.

wan2 ISP

wan1 will have my forti AP

dmz will have my nas/plex server

other will have device.

 

I tried to create a software switch so dmz wan1 and all internal port will be on the same subnet

In the setting the DMZ and wan1 port are not available to be add to the software switch.

 

FGT60E4Q16057090 # config system switch-interface

FGT60E4Q16057090 (switch-interface) # edit softsw_test new entry 'softsw_test' added

FGT60E4Q16057090 (softsw_test) # set member ? *interface-name Physical interface name.

FGT60E4Q16057090 (softsw_test) # set member

 

thanks for your help

 

Dan

 

    2 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    August 30, 2018

    Based on my partial-exhaustive/elimination tests with 60D, your immediate problem seems to be because:

    1. your DMZ likely has an IP configured. You have to remove it.

    2. looks like it doesn't like mode=dhcp on wan1. It seems to need to be static.

    3. "set vdom root" is required before you can see the member candidate regardless if you're using vdoms or not. Similar to vlan interface creation.

     

    But I don't recommend your config. Because you would eliminate the main purpose of firewalls: controlling traffic/access between interfaces with policies. I would never do that.

    Toshi_Esumi
    SuperUser
    SuperUser
    August 30, 2018

    And, it should be obvious but:

    4. internal hard-switch interface is referred by DHCP server and has an IP configured. You need to remove both.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!