Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Pang_Seng_Hwee
New Contributor

802.1p CoS on WAN port

Hi, Is it possible to set 802.1p CoS on the wan port? Need to set priority 4 of the 802.1p CoS on 1 of the wan port so that I can get the dhcp from ISP.
4 REPLIES 4
emnoc
Esteemed Contributor III

So your uplink port for your an is using tagging? FYI ..... COS and it bits are in a layer2 portion of the ethernet frame and only with 802.1q tagging. Never heard of a DHCP server using layer2 tagging to assign dhcp-scopes. Are you sure your not mistaken this for DHCP option 82 ? option82 is basic a relay agent information option and has nothing todo with 802.1p. Also I' m not ever sure if that ' s something supported on a Fortigate and for assignments of address for it' s own interfaces.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Pang_Seng_Hwee
New Contributor

Yes, the uplink port is using vlan tagging. Info as below, trying to get the MioTV working. If just set VLAN 20 not able to work, but VLAN 10 is working so I guess it is really that 802.1p. 1) Singtel uses the following VLAN IDs 10 Internet 20 MioTV 2) If you want MioTV to connect to your Cisco router, note that the 802.1p value for the port leading to the set top box should be set to 4, otherwise the MioTV set top box will never get a DHCP reply from Singtel side. Just checking if it can be done on the FortiGate 60c GEN2 running on FortiOS 5.0 Patch 1. Before I decide if I want to upgrade my router to either the newest FortiGate 60C or another Brand of router that can do that.
emnoc
Esteemed Contributor III

I think you should open a case with fortinet-TAC. I don' t know where you could begin to manipulated cos settings on a interface and for dhcp. This might be a feature request or start of a feature request if they get enough persons like you that are running into this and using singtel. Now with that said, I don' t even see how you could get away with this requirement in a cisco router, so before you go purchasing a basic cisco router, you might want to research the hardware requirements. A cisco switch might be doable, but a cisco router , I would have to say no way can you set the cos value for a tagged interface. Qs: Have they given you any sample configurations? Have you looked at installing a switch in between your fortigate and maybe some how set the cos value? or what does the typical home user deploy when using that service? Why do they even need this if the two tags are unique? To me, it seems very restrictive approach with handing out dhcp-assignments.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Pang_Seng_Hwee
New Contributor

Thanks for the advise. The ISP did provide a consumer class router (2Wire) which is able to do it but it is very restrictive and it' s LAN to WAN and WAN to LAN performance is quite low from all the reviews I read. So far the other router band which I know is Asus which does' t have dual wan and vpn function. I have been using FortiGate 60a to FortiGate 60C GEN 2 for now, so I hope to continue using their router if possible as it meets my requirement of dual wan and vpn function. Others have use layer 2 switch and place it in front of the router and have success with it. It is another point of failure so I will only consider it if all the dual wan business class router with VPN function don' t work. They did not give out any sample configuration, most of the info which was shown was provided by users who experimented with the network to find the info. That VLAN 20 is only for video, which I guess they are following the 802.1p standard of setting it to 4.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors