Skip to main content
Spoil-Equation
Explorer
January 19, 2023
Solved

FG FS FAP stack and VLAN not getting DHCP

  • January 19, 2023
  • 5 replies
  • 3431 views

I wonder how others address this, seemingly, simple config using FG-80F with FS-108E-FPOE and FAP-433F. How would you connect/configure this (an overview will suffice):

  1. FG and FS on 7.2.3, FAP on 7.2.1
  2. All 6 ports of FG belong to a VALAN 10 for wired clients
  3. VLAN 10 also has wireless clients that should be bridged to its wired clients
  4. port 8 of FS is connected to FG port a via fortilink
  5. ports 1-6 of SW belong to VLAN 20 for wired clients
  6. VLAN 20 also has wireless clients that should be bridged to its wired clients
  7. So, for FAP only port 7 available on FS, and port b on FG (POE not necessary for FAP, could be powered by a power supply). In absolute worst case, port 6 of FG could be freed for FAP

My problem is where and how to connect FAP? If a new FAP management VLAN created on SW and FAP connected to FS port 7, then VLAN 20 devices (wired and wireless) are ok but VLAN 10 wireless clients not getting IPs; if FAP management interface is created on FG by removing port b from fortilink, then VLAN 10 clients (wired and wireless) are ok but VLAN 20 wireless devices not getting an IP.

 

Any info or pointers would be appreciated

 

Best answer by gfleming

If your FortiGate switch ports are always going to be separate from those on your FortiSwitch (i.e. FGT will always only have VLAN10 and FSW will always have only VLAN20 and other VLANs outside of VLAN10) then you can just keep VLAN10 off the FortiLink/FSW and manage it on the FGT switch ports only.

 

The caveat with that solution is that your WiFi clients will never be able to join VLAN10 directly. However, using Firewall Policies you can allow devices from other VLANs to access devices like printers in VLAN10 and vice versa.

 

If you want VLAN10 integrated on your FSW and FAP then you'll need to use the physical bridge link for VLAN10 between the FSW and the FGT as I described before. That way if you want WiFi Clients existing directly in VLAN10 you can have the FGT-connected devices also participating in VLAN10.

 

It might simplify things if you put your Wi-Fi clients into their own VLAN and use Firewall policies to allow access to/from the Wi-Fi VLAN and the other Wired VLANs. You can also join some of your VLANs into an Interface ZONE and in that case you do not need any policies to allow access to-from the VLANs.

5 replies

gfleming
Staff
Staff
January 19, 2023

Alright. FortiLink is tricky because while it allows you to manage all of your switch ports and AP from the FortiGate it does not manage or integrate the switchports that exist on the Firewall! VLAN 10 on the FortiSwitch has no knowledge of VLAN10 on the FortiGate. 

 

So you either have to not use your switch ports on the Firewall or consider a couple solutions:

- A separate physical link between a FortiSwitch port configured for VLAN10 connected to one of the FortiGate switch ports (which should be configured as untagged) to bridge and connect those two domains

- Running the FortiSwitch in standalone mode and bridging everything that way through the uplink

 

For the AP jjust connect it to the FortiSwitch port 7 and set up a AP MGMT network as the native VLAN and tag VLAN 10 and VLAN 20. Two SSIDs configured, one for VLAN10 wireless clients and one for VLAN 20 for other wireless clients.

Spoil-Equation
Explorer
January 19, 2023

@gfleming - thank you for a quick and tremendously informative response!

Running FS in standalone mode is out of the questions, that puts this option to rest.

Now, are you saying that I can:

  • keep FS port 8 connected to FG port a for FortiLink
  • configure FS port 7 as native VLAN 20 (did you make a typo in you response referring to this VLAN as 10?)
  • remove FG port 6 from VLAN 10 (to make it untagged)
  • connect FS port 7 to FG port 6

Will the above make FG aware of FS VLAN 20 or will it make FS aware of FG VLAN 10?

gfleming
Staff
Staff
January 19, 2023

Close. I was suggesting you create a new VLAN for FortiAP management (FortiAP's will get an IP address in this VLAN and will be used for connecting back to the FortiGate for management). Let's call it VLAN40.

 

On FS Port 7 make VLAN40 native, FortiAP will connect to that port and receive an IP address from VLAN40 DHCP scope and communicate to FortiGate this way.


Port 7 will also have VLAN10 and VLAN20 tagged for wireless client access. It sounds like you have two wireless networks, right? So two SSIDs, one configured to be VLAN10 and another SSID to be VLAN20. When clients connect to either SSID their packets will be tagged for the respective VLAN and be connected appropriately.

 

If you want the ports 1-6 on the FortiGate to also participate in VLAN10 then keep them untagged, no VLAN configuration needed. Set a port on the FS (not port 7 because that's used for the AP). Perhaps port 6 or something. Native VLAN10 on port 6. Physically connect port 6 to port 1 or 2, 3 4 5 or 6 on the FGT and this will naturally extend VLAN10 to the FortiGate switch ports.

 

Make sense?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.