Skip to main content
lovejit
New Member
May 28, 2018
Solved

Fortigate Firewall : Lan port shoul be L2 Hardware switch Interf or L3 Physical Interface

  • May 28, 2018
  • 1 reply
  • 13799 views

Hello Guys,

 

I have Fortigate 100D installed on multiple sites,  and everything is working. Only difference is that some firewalls have Lan port (which goes to internal network) as L3 Physical Interface with static IP whereas other firewalls have L2 type Hardware switch interface.

 

Please explain how it makes difference in networking, Which is Industry standard and why ?

 

    Best answer by Nicholas_Doropoulos

    Hi,

     

    It depends on the Fortigate's mode of operation. The modes are 2:

     

    NAT mode (aka Router mode) whereby the firewall acts as a layer 3 device that forwards packets. As such, the firewall's interfaces are assigned IP addresses. This is the default mode.

     

    Transparent mode (aka Bridge mode) enables the firewall to act as a layer 2 device that can either block or forward frames. This mode is usually used for deployments whereby the user doesn't want to re-configure his IP addressing scheme of his network to implement Fortigate.

     

    I hope that helps.

    1 reply

    Nicholas_Doropoulos
    New Member
    May 28, 2018

    Hi,

     

    It depends on the Fortigate's mode of operation. The modes are 2:

     

    NAT mode (aka Router mode) whereby the firewall acts as a layer 3 device that forwards packets. As such, the firewall's interfaces are assigned IP addresses. This is the default mode.

     

    Transparent mode (aka Bridge mode) enables the firewall to act as a layer 2 device that can either block or forward frames. This mode is usually used for deployments whereby the user doesn't want to re-configure his IP addressing scheme of his network to implement Fortigate.

     

    I hope that helps.

    lovejit
    lovejitAuthor
    New Member
    May 28, 2018

    I already aware of these modes and our all firewalls are configured with NAT mode , but still some firewall LAN port is configured as L2 port and some are L3 ports.

     

    still confuse ?