Skip to main content
lexagl
New Member
May 27, 2025
Solved

"Fortiextender LAN Extension" interface type in Fortimanager?

  • May 27, 2025
  • 1 reply
  • 1274 views

Hi all,


I'm doing a trial setup of some FortiExtender FEX-202Fs with my existing Fortigate 91Gs which are managed via a FortiManager VM. I plan on using these as LAN extenders for remote microsites. I've managed to get the FEX units working well with the FGTs on their own, but the trouble comes when I try to use FMG to create firewall policies involving the FEX interfaces. 

 

In the FGT UI, I can see the FEX units correctly appearing under the "LAN Extension" category. Firewall polices work fine when configured directly on the gates. However, when the FGT configs are imported into FMG these same interfaces appear as the "VLAN" type. I am then not able to select these interfaces when making firewall polices. I'm assuming this is because the "role" variable on the erroneous VLAN page for these interfaces is set to "Undefined". Unfortuantely I am not able to change the interface role, as an error message appears notfying that "VLAN ID must be between 1-4096", but the option to set a VLAN ID is greyed-out ... all of this despite the interface not actually being of the VLAN type in the first place.

 

I see in FMG there is an option to create a Fortigate interface of the "FortiExtender WAN extension" type, but I do not see a corresponding option for a "LAN extension" type.

 

Firmware versions involved:

Fortigates: 7.4.7 build2731

Fortimanager: 7.4.6 build2588

 

Images:

LAN Extension as it appears directly in the Fortigate UI:

fortigate-view.png

 

 

 

 

 

 

 

 

 

 

 

 

Same interface as it appears in the Fortimanager UI:

fortimanager-vew.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Edit interface menu in Fortimanager for the above:

fortimanager-edit-interface.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Sorry for the long post. Thanks in advance!

Best answer by lexagl

Correction to the above, I’ve found the only necessary steps are to remove the Fortigate and then add it back to the Fortimanager.

 

I’m going to mark this as the solution, though it’s certainly a bug with Fortimanager that needs fixing.

1 reply

funkylicious
SuperUser
SuperUser
May 27, 2025
lexagl
lexaglAuthor
New Member
May 27, 2025

I followed those steps and the FEX shows correctly in the FMG Extender Manager page as a LAN extension. However, the interface still shows incorrectly as a "VLAN" type in the gate's page under device manager. 

 

fortimanager-exender-manager.png

 

 

funkylicious
SuperUser
SuperUser
May 27, 2025

may try importing again the config from the device and hopefully it makes another mapping type.

"jack of all trades, master of none"