Description | This article discusses the considerations one such take before implementing/Creating VLANS in FORTIOS. |
Scope | FortiGate. |
Solution |
The scope of VLAN which is available on FortiGate is [ 0 - 4094].
When configuring a network or setting up a VLAN interface, it is necessary to be aware that VLAN ID: 1 cannot be configured when creating a new VLAN interface on FortiGate.
Mostly, an RPF will encounter a check failure, meaning it cannot route the traffic back to the source which in this case, is a source IP behind the VLAN which is tagged as VLAN ID 1.
diagnose debug flow filter addr x.x.x.x <----- (x.x.x.x is the source IP behind the VLAN). diagnose debug flow show iprope enable diagnose debug flow show function-name enable diagnose debug flow flow trace start 100 diag de enable
To stop:
diag de disable |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.