Question
VLAN subinterfaces not communicating
Howdy, I am currently running an EOL Fotrigate 100A (3.00 559). I am trying to move to a newer Fortigate 60D (5.0 something) no wireless. I have created several vlan sub-interfaces under the INTERNAL interface. All the vlans are coming from the same switch then to the FGT for routing internally and if appropriate to the Internet. This worked fine on FGT100A not so much on the FGT60D. There are some physical differences between the FGT100A and the FGT60D but it doesn' t seem they are so different that what was done on the FGT100A shouldn' t work on the FGT60D. Using vlans 101, 102 103, 104 (there are more but I am trying to keep this brief). All vlans are on separate ports on the switch and the FGT unit. When all are connected, only the lowest numbered vlan, 101, can talk to the FGT60D. On vlan 101 I can ping the gateway address on the FGT and I can ping the other gateways on the FGT. None of the other vlans can get a response from the FGT even from thier respective gateway. If I disconnect vlan 101 then vlan 102 will start working, If 101 and 102 are disconnected then vlan 103 will start communicating. There is another vlan (150) that is a sub-interface of the DMZ port. the 150 vlan is coming from the same switch as the other vlans under the INTERNAL interface. The 150 vlan talks to the FGT regardless of the connect state of the INTERNAL vlan sub-interfaces. However no traffic passes through from the 150 vlan to any of the INTERNAL vlan sub-interfaces (at least which ever one is working at the time) or vice-versa. If the vlans are under different physical interfaces they can concurrently communicate to the FGT60D but traffic will not pass from one to the other ( yes, the firewall policies do exist that should allow the traffic to pass). If the vlans are under the same physical interface, only 1 vlan can communicate to the FGT60D. This same setup works fine using the EOL FGT100A. What am I missing? What has changed that this setup does work on the FGT60D? FWIW the switch is an old Dell 5324. Although it is the FGT unit that is being changed out, I understand it may require changes to the switch rather than to the FGT unit.