Skip to main content
Arafattamim
New Member
August 19, 2025
Question

Redundant Uplink

  • August 19, 2025
  • 1 reply
  • 383 views

Hello Community,

We are planning to add a second uplink on our FortiGate firewall. Currently, VLAN 92 and VLAN 93 are configured as sub-interfaces under Port13.

Now we have a requirement to:

  • Add Port14 together with Port13.

  • Create a Redundant Interface (Port13 + Port14),

  • Move all existing VLAN sub-interfaces from Port13 to this new redundant interface.

My questions are:

  1. After creating the Redundant Interface, do we need to reconfigure all existing firewall policies, routes, and objects that are currently using Port13?

  2. Is there a way to migrate VLANs from Port13 to the new redundant interface without deleting/recreating all VLAN sub-interfaces manually?

  3. Does this change affect existing VPNs, static/dynamic routing, or HA configurations?

  4. Are there any best practices or recommended steps to perform this migration in production to avoid downtime?

  5. Can anyone share official Fortinet documentation or KB articles regarding redundant interface + VLAN sub-interface configuration?

  6. In GUI/CLI, which option/menu should we follow to configure this redundant interface properly?

 

1 reply

AEK
SuperUser
SuperUser
August 19, 2025

Hi Arafat

  1. Yes, but if you use interface migration or zones then you will not change any policy (using zones is good admin practice)
  2. You should be able to do it with interface migration: https://docs.fortinet.com/document/fortigate/7.0.0/new-features/885870/interface-migration-wizard
  3. Yes it does, if your VPN is built on port13. But the interface migration wizard should resolve this
  4. 5. & 6. When you say redundant, do you mean LACP? Or do you mean standalone interfaces? Or is port13 & port14 part of FortiLink?
AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!