I’m a student whose only ever worked with Cisco and I can’t seem to grasp how vlans work in fortinet, I’m doing a lab with a fortigate and a fortiswitch but I am confused how vlans work, what’s the difference between a vlan created in interfaces and one created in fortiswitch ports? How do I connect the cables so the vlans work?
hi,
they work the same as in Cisco.
on the FortiGate you create a interface where you select the parent/physical interface and the vlan id to tag it ( subinterface ).
on the FortiSwitch you create the vlan and tag it on the port ( trunk interface ) - https://docs.fortinet.com/document/fortiswitch/6.4.6/administration-guide/146333/vlans-and-vlan-tagg...
these 2 interfaces need to be directly connected between them and should work.
https://docs.fortinet.com/document/fortigate/7.0.0/ngfw-deployment/487675/lans-and-lan-segmentation
On Fortinet it’s the same logic as Cisco, just split in two places, and that’s why it feels confusing at first.
- A VLAN on the FortiGate is like creating a sub-interface on a Cisco router (int g0/0.10 vlan 10).
- A VLAN on the FortiSwitch is like configuring the switchport VLANs on a Cisco switch (access or trunk with tags).
You connect the FortiGate port to the FortiSwitch uplink, tag the same VLAN IDs on both sides, and it works exactly like router-on-a-stick on Cisco.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-Inter-VLAN-Routing-on-the-FortiG...
https://pingmynetwork.com/network/ccna-200-301/intervlan-routing
| User | Count |
|---|---|
| 2787 | |
| 1423 | |
| 812 | |
| 746 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.