Skip to main content
capricorn80
New Member
August 7, 2018
Solved

WAN connectivity to Switch and then to Fortigate

  • August 7, 2018
  • 1 reply
  • 11073 views

Hi!

 

We are using Vlans based topology where we have vlans on distribution layer switches and few SVI lives on core switch.

We have fiber coming from our ISP provider that I want to terminate in in our distribution switch as I have 10G interface in my distribution switch.

 

The issue is that we have IP scheme our ISP and if I terminate the Fiber directly into our Fortigate FW then everything works but our 100E is just 1G sfp and we have one 10 G internet line. 

 

The only way is to somehow terminate this to distribution switch to get 10G connection but I am coming up with any idea how I an design this because of the VLAN.

 

Any suggestion with this?

 

Thanks 

    Best answer by Toshi_Esumi

    Terminate the ISP circuit at the 10G port on the switch and make it as an access port for a VLAN, let's say vlan 99. Then another port (GigE) on the same switch as the same access port for vlan 99 to connect to your FG100E.

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    August 7, 2018

    Terminate the ISP circuit at the 10G port on the switch and make it as an access port for a VLAN, let's say vlan 99. Then another port (GigE) on the same switch as the same access port for vlan 99 to connect to your FG100E.

    capricorn80
    New Member
    August 7, 2018

    Thanks Toshi. I will try this.

     

    Can you please tell any link which explain about the theory of such concept. I never heard or read this before.

     

    Really want to read about it.

    Toshi_Esumi
    SuperUser
    SuperUser
    August 7, 2018

    It's general "Layer2 switching" concept with VLANs you can find on the internet or some books like Cisco/Juniper certification, etc. If the 10G circuit constantly pumps in more than 1G FGT WAN interface can take, they would eventually overflow the buffer at the switch. But I assume the circuit's committed bandwidth isn't way over 1Gbps, and actual traffic wouldn't hit that level all the time.