Skip to main content
Theo4
Explorer
May 4, 2024
Solved

Using FortiSwitch Interfaces in multiple VDOMs

  • May 4, 2024
  • 8 replies
  • 6762 views

Has anyone been able to move FortiSwitch interfaces to a different VDOM than where FSW is? 

 

I added FortiSwitch to root VDOM and moved some interfaces to another VDOM following this guide: https://docs.fortinet.com/document/fortiswitch/7.4.2/fortilink-guide/801172/multitenancy-and-vdoms

 

I created a VLAN on the new VDOM and assigned to the switch ports. However, when connecting a device to one of these ports, I'm unable to get the device to have an IP assigned from the VLAN. 

 

When checking "FortiSwitch Clients" list, I find the connected device under "root" instead of the new VDOM, and It's assigned the default VLAN 1 from root, rather than the VDOM assigned to the port.

 

I'm running FortiOS 7.4.3 on FGT and FortiSwitch 7.4.2.

Best answer by Theo4

The issue got fixed after upgrading FortiOS to 7.4.4 and FortiSwitch to 7.4.3, so I assume it's a bug, although can't find a matching issue in the release notes. 

8 replies

dbu
Staff
Staff
May 4, 2024

Hi @Theo4 ,

Is the DHCP server enabled for this VLAN interface ?
What happens if you assign a manual IP address to the device ? 

You mentioned it is showing under vdom  root, have you done the export of the interface to the tenant VDOM ?

Here is a good article on how to troubleshoot the DHCP flow :
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Diagnosing-DHCP-on-a-FortiGate/ta-p/192960

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-DHCP-relay-issue/ta-p/215535

Theo4
Theo4Author
Explorer
May 4, 2024

Hi, 

 

- DHCP server is enabled. 

 

- I assigned a manual IP to the device. It keeps sending ARP to FGT without reply, because it wasn't assigned to the intended VLAN. 

 

- I did export the interface to the tenant VDOM. the switch port is showing under the tenant VDOM already. 

 

- Eliminating DHCP still didn't fix the issue, so I don't think it's a DHCP problem. Adding to that the fact that the device is landing in root VDOM and being assigned the wrong VLAN. 

pushparaj2
New Member
May 6, 2024

I don’t think (though can’t be certain) that it’s work, fortilink is a single interface (made up of many physicals) but the single fortilink has to reside in one vdom and tha vdom can only be active on one cluster node. I suspect that the interface you use on node b with the split mode wouldn’t come up.

Theo4
Theo4Author
Explorer
May 7, 2024

Hi pushparaj2

 

There is no cluster. This is a single FortiGate node. There is also no split mode. FortiLink consists of two physical interfaces and they are both active. 

 

The idea here is to split FortiSwitch ports into multiple VDOMs, not FortiLink interfaces, similar to what's described here:  https://docs.fortinet.com/document/fortiswitch/7.4.2/fortilink-guide/801172/multitenancy-and-vdoms

hbac
Staff
Staff
May 6, 2024

Hi @Theo4,

 

What is the native VLAN of the switch port you are connected to?

 

Regards, 

Theo4
Theo4Author
Explorer
May 7, 2024

It's a new VLAN I created on the new VDOM. 

hbac
Staff
Staff
May 7, 2024

Hi @Theo4,

 

Please make sure you assign that new VLAN as a native VLAN of the switch port. Please refer to https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-sd-branch-deployment-guide/352373/assigning-vlans-to-switch-ports

 

Regards, 

Theo4
Theo4AuthorAnswer
Explorer
May 16, 2024

The issue got fixed after upgrading FortiOS to 7.4.4 and FortiSwitch to 7.4.3, so I assume it's a bug, although can't find a matching issue in the release notes. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.