Description |
This article describes some limitations that should be considered when implementing/creating VLANs on the FortiGate. More specifically, the available range of VLAN IDs for a VLAN sub-interface can be limited depending on the parent interface that is selected. |
Scope | FortiGate, VLANs. |
Solution |
For reference, the total range of VLAN IDs is from 0 to 4095. However, when setting VLAN IDs on a FortiGate interface (such as creating a VLAN sub-interface or VLAN Switch), there are some limitations to be aware of:
Note:VLAN ID 0 is not used for network segmentation but mainly used for qos tagging.
To troubleshoot issues related to VLAN ID misconfigurations, try using tools on the FortiGate, such as the Packet Sniffer and Debug Flow, to check for incoming/outgoing packets. In particular, keep an eye out for cases where traffic egresses as tagged traffic and yet returns as untagged or differently-tagged traffic:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.