Skip to main content
Lapecandcie
New Member
November 26, 2015
Question

Problem with vlan subinterface configuration

  • November 26, 2015
  • 3 replies
  • 4379 views

Hello,

 

I am in interface mode, I have configured vlan subinterfaces Under the internal2 link of my Fortigate 200A. The problem is that we are unable to ping the IP address of these interfaces from a PC on the network.

I have created 5 vlans : 182, 183, 184, 185, 186 on my Cisco switch. The internal 2 link is connected with a trunk interface switch with the 5 tagged vlans. I have created also policies for these interfaces. The problem is that the internal2 ip address is also unreachable.

 

Could you please help me, please?

 

Thank you in advance for your support

 

Chris

    3 replies

    shane_85
    New Member
    November 26, 2015

    have you allowed pings on the interfaces?

    emnoc
    New Member
    November 26, 2015

    Agree, but the cli cmds diag debug flow and diag sniffer packet are your 2 best friends. It will confirm your layer2 tags are correct at the packets made it from the cisco switch with a 802.1q tag.

     

    ede_pfau
    SuperUser
    SuperUser
    November 26, 2015

    Have you made sure that your PC is part of the VLAN whose gateway you're pinging? And if so, how?

     

    (rationale: if the PC is not in VLAN 187 it will ping on VLAN 1 and won't be able to reach the other network)

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!