We are converting checkpoint configurations to fortigate (finally getting rid of it)
But I have seen the interface setting and here is something I am not used to it
In Checkpoint the LAG interface itself (the physical) has a network without VLAN
the Forticonverter converter exactly the same settings. see screenshots bellow:
I am used to put all IP addresses and betworks to logical interfaces with VLANID
So my question is, will this work normally in fortigate? with VLAN ID 1 ? untagged ? can this interface (the physical) be assigned to policies later ?
Thanks
Thanks
Solved! Go to Solution.
yes, it should work normally and you can use it later in firewall rules.
as for the VLAN ID, this can be verified/viewed and the switch/PO interface on what native vlan is set but it should work as intended.
yes, it should work normally and you can use it later in firewall rules.
as for the VLAN ID, this can be verified/viewed and the switch/PO interface on what native vlan is set but it should work as intended.
Thank you, appreciated!
For the SW (Aruba) it is native vlan 1
So it is the same in the Physical link aggregation in fortigate?
Thanks
Created on 08-22-2025 05:19 AM Edited on 08-22-2025 05:19 AM
it should be ok.
you would need to match the LACP params on the FGT to the ones on the SW as for mode active and speed/rate fast .
User | Count |
---|---|
2555 | |
1356 | |
795 | |
648 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.