Skip to main content
aaans
New Member
March 2, 2017
Question

VLAN

  • March 2, 2017
  • 4 replies
  • 5294 views

Hi there i need to pass trafic trough fiber between 2 buildings , and passing two different networks, my internal, and one for my access points.

Already created 2 vlan i have one Fortigate 60D, 1 HP layer3 Switch and on the other building one switch 1810G-8 that i divided the first 4 port to untagged on vlan1 and 5,6,7,8 untagged on vlan 2 leaving the default vlan all ports excluded(E)

Need help please....how do i configure the fortigate to receive traffic from 2 vlans? on port 4 for instance?

 

    4 replies

    ede_pfau
    SuperUser
    SuperUser
    March 2, 2017

    hi,

     

    and welcome to the forums.

    In order to use VLANs across switches you need to configure them as 'tagged'. The packets then carry a VLAN label (tag) with the VLAN ID in it. This way, the switch on the receiving side can decide to forward or discard them.

     

    VLANs on a FGT are handled with VLAN ports. These are virtual ports built upon a physical port. If you look at System>Interfaces, Create New, you've got the choice to create a VLAN port. Assign a VLAN ID and an interface IP address plus network mask. Connect the switch port carrying that VLAN to the physical port the VLAN is created on.

     

    VLAN ports on a FGT always are tagging VLAN ports.

     

    Then create policies to allow traffic between (phys) ports and VLAN port, or VLAN port to VLAN port etc. just like between 'real' interfaces.

     

    More info in the Reference Guide (docs.fortinet.com).

    aaans
    aaansAuthor
    New Member
    March 3, 2017

    Here let me show u what i have:

     

     

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.