Skip to main content
qqh452821000
New Member
December 20, 2018
Solved

FortiGate use sub-vlan how to communicate with PC

  • December 20, 2018
  • 7 replies
  • 8896 views

Hello everyone

 

I have a question about fortigate use sub-vlan how to communicate with switch

I use EVE-LAB doing some test.

Here is my topo

 

 

and here are my switch G0/4 conf:

switchport trunk encapsulation dot1q switchport trunk native vlan 999 switchport mode trunk

 

PC1 ip address is 192.168.1.1/24

PC2 ip address is 192.168.2.1/24

 

PC1 should have been able to ping 192.168.1.254

PC2 should have been able to ping 192.168.2.254

 

But I use EVE-LAB, it is timeout . 

 

Is it something wrong with my configuration?

 

There is another question, Is it need to configure switchport trunk native vlan 999 on switch?

Does the fortigate vlan 1 have a tag?

 

Any body have any thought?

 

Best Regards,

Tim

Best answer by Toshi_Esumi

If they're in FGT's arp table, you should be able to ping PCs from FGT. Have you tried? If this works, only other possibility is "trusthost" config in admin users is prohibiting from pinged. Include 192.168.1.0/24 and 2.0/24.

 

As I wrote first, untagged interface is the "port3" parent interface. You need to configure 1.254 on it without Vlan1 subinterface.

7 replies

Toshi_Esumi
SuperUser
SuperUser
December 20, 2018

On fortigate "VLAN1" is tagged. On Cisco Vlan1 is default native-vlan for all ports and untagged. You need to configure 192.168.1.254/24 on port3 parent interface.

Is the second vlan 999 as in the switch config or 119 as in the image?

Toshi_Esumi
SuperUser
SuperUser
December 20, 2018

Sorry, I misread "native vlan" config. Then it's up to the port config for the PC1 and PC2. Did you configure those access ports vlan 1 and 119 respectively? And verify those VLANs are included on G0/4 with show int trunk.

 

Toshi_Esumi
SuperUser
SuperUser
December 20, 2018

Or, the new VLAN subinterfaces are not configured to allow pinging (set allowaccess ping) on the FGT.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.