Skip to main content
ahmadking22
Explorer II
August 6, 2024
Solved

VLANS

  • August 6, 2024
  • 9 replies
  • 2546 views

Hello

I have FotrtiGate100F

I have 3 building in my company each building has connection to MY FortiGate 

Building A - connect to port 17   ( I create VLAN 10 for LAN and  VLAN 11 for AP )

Building B - connect to port 18   ( I create VLAN 12 for LAN and  VLAN 13 for AP)

Building C - connect to port 19    ( I create VLAN 14 for LAN and  VLAN 15 for AP)

I need All AP  in all Building to take IP Address from same range anyone can help me 

thanks for all

best regards.

Best answer by ahmadking22

 I have solved this problem

i putted more interface as switch after that i create VLAN for LAN ,AP and Server

9 replies

ozkanaltas
Valued Contributor III
August 6, 2024

Hello @ahmadking22 ,

 

You can do this with VDOMs. If you create separate VDOM for each building, you can use the same subnet for all buildings. 

ebilcari
Staff
Staff
August 6, 2024

If I get it right, you want to use a single subnet/VLAN for all the APs in the network for all the buildings. To span the same VLAN on multiple ports of the FGT a hardware switch can be configured. It allows to use the same L2 network through different FGT ports.

Emirjon
AEK
SuperUser
SuperUser
August 6, 2024

Hi Ahmad

If I understand your requirement, you need the same SSID on all APs.

Single SSID = Single Interface = Single range

AEK
ahmadking22
Explorer II
August 6, 2024

yes exactly i need like this

 

AEK
SuperUser
SuperUser
August 6, 2024

So you create a FortiAP profile, add the SSID(s) to this profile, then assign the profile for all your managed APs.

AEK
spoojary
Staff
Staff
August 6, 2024

Configure DHCP servers for each VLAN associated with the APs in each building.

Enable the shared-subnet feature for each DHCP server to allow IP address allocation from the same range.

Set up DHCP relay agents for each building to forward DHCP requests to the FortiGate.

 

https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/486838/dhcp-shared-subnet-new

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/486838/dhcp-shared-subnet

https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/783526/dhcp-servers-and-relays

Toshi_Esumi
SuperUser
SuperUser
August 6, 2024

Interestingly this many interpretations and suggestions. Yet another one.
I interpreted as [VLAN11+13+15] with one DHCP range.
How about combining all three VLAN interfaces into one software-switch? This can have only one interface/GW IP and subnet, therefore needs only one DHCP range.

Toshi

sw2090
SuperUser
SuperUser
August 7, 2024

maybe the most easiest way would be to create a dhcp relay on every vlan that relays to one specific dhcp server that has a pool covering all three vlan so they can get ip from the same nets.

 

ahmadking22
ahmadking22AuthorAnswer
Explorer II
August 12, 2024

 I have solved this problem

i putted more interface as switch after that i create VLAN for LAN ,AP and Server

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!