Created on 09-17-2023 07:53 PM Edited on 09-19-2023 09:22 PM By Anthony_E
Description |
This article describes that when configuring VLAN interfaces on FortiGate, it is possible to encounter two common VLAN protocols: 802.1Q and 802.1AD, also known as QinQ (Double VLAN and clarifies the differences between these VLAN protocols and how they are configured on FortiGate devices. |
Scope | FortiGate. |
Solution |
VLAN Protocol 802.1Q: 802.1Q is the most widely used VLAN tagging protocol. It allows the insertion of a 4-byte VLAN tag (or VLAN header) within the Ethernet frame. The VLAN tag consists of a 12-bit VLAN ID (VID), which can represent up to 4096 unique VLANs. (Maximum value is 4094).
Key Characteristics:
Use Cases:
VLAN Protocol 802.1AD (QinQ): 802.1AD, commonly referred to as QinQ or Double VLAN tagging, extends the capabilities of 802.1Q. It allows the nesting of VLAN tags within another VLAN tag. QinQ effectively creates a 'VLAN within a VLAN', allowing for more extensive network segmentation. Supports a large number of VLANs due to nesting. The outer VLAN tag and inner VLAN tag each have their VLAN IDs.
Key Characteristics:
Use Cases:
Configuring VLAN Interfaces on FortiGate:
Related Article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.