Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
leblanda
New Contributor II

DMZ and unused Wan port on switch not working

My setup

fortigate 60e

FortiOS v5.6.5 build1600 (GA)

 

I need more port in my network and need to be al on the same subnet.

wan2 ISP

wan1 will have my forti AP

dmz will have my nas/plex server

other will have device.

 

I tried to create a software switch so dmz wan1 and all internal port will be on the same subnet

In the setting the DMZ and wan1 port are not available to be add to the software switch.

 

FGT60E4Q16057090 # config system switch-interface

FGT60E4Q16057090 (switch-interface) # edit softsw_test new entry 'softsw_test' added

FGT60E4Q16057090 (softsw_test) # set member ? *interface-name Physical interface name.

FGT60E4Q16057090 (softsw_test) # set member

 

thanks for your help

 

Dan

 

2 REPLIES 2
Toshi_Esumi
Esteemed Contributor III

Based on my partial-exhaustive/elimination tests with 60D, your immediate problem seems to be because:

1. your DMZ likely has an IP configured. You have to remove it.

2. looks like it doesn't like mode=dhcp on wan1. It seems to need to be static.

3. "set vdom root" is required before you can see the member candidate regardless if you're using vdoms or not. Similar to vlan interface creation.

 

But I don't recommend your config. Because you would eliminate the main purpose of firewalls: controlling traffic/access between interfaces with policies. I would never do that.

Toshi_Esumi
Esteemed Contributor III

And, it should be obvious but:

4. internal hard-switch interface is referred by DHCP server and has an IP configured. You need to remove both.

Labels
Top Kudoed Authors