Skip to main content
zpGmail
New Member
September 21, 2020
Solved

Forti VLANs with Cisco Switch

  • September 21, 2020
  • 13 replies
  • 19539 views

Hello, folks.

 

I'm fairly new to FortiGate and I'm in the process of configuring an 80F to replace a Cisco RV320 router. The RV320 has 4 sub-interfaces tagged with their respective VLANs:

- x.x.0.1 (default), x.x.10.1 (vlan10), x.x.20.1 (vlan 20), x.x.30.1 (vlan 30)

 

The Cisco core switch has virtual interfaces for each VLAN:

- x.x.0.2 (default), x.x.10.2 (vlan10), etc.

- Each VLAN interface points to a Windows server for a DHCP-helper address

- The DHCP scopes for each VLAN subnet points to the respective switch virtual interface (x.x.x.2) for its gateway

- The core switch has a single default route pointing to x.x.0.1 on the RV320

- The core switch is connected to the RV320 by single trunk port that carries all VLANs

 

As I'm setting up the 80F I thought it would be nice for each VLAN to have a dedicated physical port on the FortiGate to avoid having congestion on a single shared trunk port:

- I removed 3 ports from "internal" and configured them as standard ports (not VLAN) each with their x.x.x.1 address

- I plan to dedicate 1 core switch port for each VLAN and connect them to the respective 80F ports 1:1

- I plan to change the DHCP scopes for each subnet to point to the x.x.x.1 address of the 80F ports (the reason for using x.x.x.2 previously was to keep inter-VLAN traffic on the switch and off the trunk to the RV320)

 

I've done something similar for a Guest network on a different Forti device but in that instance the VLAN was carried through the network directly to the (untagged) FortiGate port which handed out DHCP itself. In that case it worked just fine.

 

Am I going about this the right way or is there a better/easier way? Can I setup a DHCP-helper address on the physical Forti interfaces? Is there benefit to configuring the Forti ports as VLAN interfaces?

 

Edit:

What about using a 4-port aggregate on the Forti to a 4-port Etherchannel on the Cisco and keeping the switch's default route to x.x.0.1?

 

Thanks!

zp

Best answer by lobstercreed

Hey Zach,

 

zp wrote:

Am I going about this the right way or is there a better/easier way? Can I setup a DHCP-helper address on the physical Forti interfaces? Is there benefit to configuring the Forti ports as VLAN interfaces?

Yes, yes, and no.  This gives you the greatest flexibility in building firewall rules and controlling (or at least logging) inter-VLAN traffic.  You absolutely can have the FortiGate do the ip-helper and you can do it from the GUI interface config by selecting Advanced when you turn on the DHCP server and changing the Mode from "server" to "relay".

 

 

zp wrote:

Edit:

What about using a 4-port aggregate on the Forti to a 4-port Etherchannel on the Cisco and keeping the switch's default route to x.x.0.1?

 

I'm not sure what the switch's default route has to do with whether you use LACP or not, but I would imagine you could use the agg and do VLANs on that interface.  Honestly, not something I've ever had reason to do but if bandwidth or VLAN expansion is a concern, maybe you want to give it a try and let us know.  :)

 

- Daniel

13 replies

lobstercreed
New Member
September 23, 2020

Hey Zach,

 

zp wrote:

Am I going about this the right way or is there a better/easier way? Can I setup a DHCP-helper address on the physical Forti interfaces? Is there benefit to configuring the Forti ports as VLAN interfaces?

Yes, yes, and no.  This gives you the greatest flexibility in building firewall rules and controlling (or at least logging) inter-VLAN traffic.  You absolutely can have the FortiGate do the ip-helper and you can do it from the GUI interface config by selecting Advanced when you turn on the DHCP server and changing the Mode from "server" to "relay".

 

 

zp wrote:

Edit:

What about using a 4-port aggregate on the Forti to a 4-port Etherchannel on the Cisco and keeping the switch's default route to x.x.0.1?

 

I'm not sure what the switch's default route has to do with whether you use LACP or not, but I would imagine you could use the agg and do VLANs on that interface.  Honestly, not something I've ever had reason to do but if bandwidth or VLAN expansion is a concern, maybe you want to give it a try and let us know.  :)

 

- Daniel

zpGmail
zpGmailAuthor
New Member
September 23, 2020

Thanks, Daniel. VLAN expansion is something I started thinking about and as of now have decided to do the LAG port so that I can add more VLANs when needed. My thought on the gateway was that I would just use the physical x.x.0.1 address with no sub-interfaces and have my L3 switch use that address as the default gateway.

 

We have a similar setup at one of our offices (what I'm working on is a side project for someone else) and that FG is apparently able to assign rules based on the source subnets even though the FG itself has no sub-interfaces on those subnets.

Toshi_Esumi
SuperUser
SuperUser
September 23, 2020

As Daniel pointed out, it's all about if you want/have to regulate inter VLAN traffic with FW policies or not. If the L3 switch route them each others, the traffic doesn't come to the FGT. And of course most of FW gears on the market can regulate traffic based on IP addresses/subnets for source and/or destination, not only FGT, as long as the traffic comes to it. 

 

sw2090
SuperUser
SuperUser
September 25, 2020

On a FGT a vlan is threated as a virtual interface too. So you can tie it to a port or switch or trunk.

You cannot configure a physical interface as vlan interface on a FGT.

 

Then you can create policies or static routes using the vlan interface as source or destination interface.

However only traffic that leaves the cisco will hit the FGT.

 

And yes a virtual vlan interface can have rather the same options as a physical one. So you could set up secondary IP(s) or dhcp server or dhcp relay on it if needed.

lobstercreed
New Member
September 25, 2020

I believe you've got it, Zach!  That should work as far as I can tell from what we've discussed.

zpGmail
zpGmailAuthor
New Member
September 25, 2020

Thank you everyone, I appreciate it!

zpGmail
zpGmailAuthor
New Member
September 27, 2020

The change-over went great! One thing that I expected to possibly be an issue was having the one sub-interface tagged as "VLAN 1". I changed the VLAN ID for that (management) VLAN and adjusted some internal addressing. Worked out just fine and will end up being more secure anyway by preventing VLAN hopping.

 

Thanks again everyone!

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!