FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.

This article notes that VLAN interface can't pass traffic properly on some FortiGate models,
when the VLAN interface is created on mangement interface.
This is due to hardware limitation of network interface on those models.


  • All FortiOS
  • FortiGate Models, Management I/F
    • FortiGate 1240B, port39
    • FortiGate 3040B/3140B, mgmt1
    • FortiGate 3950B/3951B, mgmt1
    • FortiGate 600C/800C/1000C, mgmt1
    • FortiGate 3240C, mgmt


  • Prior to FortiOS 5.0.2
Though FortiOS allows to create VLAN interface on those management interfaces, it won't work properly.
So please take care not to use Tag-VLAN on management interface in your network.

  • FortiOS 5.0.2 and later
FortiOS won't allow to create VLAN interface on those management interfaces anymore.


Related Articles

Technical Note: Network interface "mgmt" on FortiGate 100D units can not be used to create VLAN inte...