Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ChrisStankevitz
New Contributor

Create VLAN without specifying an IP address

I want to create a VLAN.  I do not want to create a VLAN Interface.  I do not want routing/gateway capability.  I do not want the FortiSwitch/FortiGate to take an IP address on this VLAN.

 

Is this possible?  I'm beginning to think that in the FortiWorld it is impossible to create a Layer2-only entity.

 

Thank you,

 

Chris

1 Solution
brycemd

Just leave the IP as default. 0.0.0.0/0.0.0.0

 

Edit:

I guess we should clarify if we are talking from the fortigate/managed fortiswitch perspective or from a standalone fortiswitch perspective.

 

From a standalone fortiswitch perspective, you do not need to specifiy any IP for any VLAN, it doesn't even ask unless you are creating a management interface. Same as really any other switch out there.

 

From a FortiGate/managed fortiswitch perspective you can set the IP to 0.0.0.0/0.0.0.0 to accomplish the same thing.

View solution in original post

5 REPLIES 5
emnoc
Esteemed Contributor III

No it's not possible in a std  L3 firewall configuration. You need a layer3 address. What are you trying to do specifically so we can understand this request?

 

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ChrisStankevitz

Hi Ken,

 

Thank you for your reply.

 

I don't want anything talking on the LAN, except some devices that I have identified.  I don't want the fortinet equipment even consuming one of the precious IP addresses on the subnet.  I want a guarantee that nothing else can transmit on the LAN -- I want routing disabled.  I don't want the firewall to even have an opportunity to allow someone else to talk on this LAN, even if misconfigured.  If the switch must have an IP address on the LAN, then I have no guarantee about any of this and instead have to trust my understanding of FortiNet, trust my configuration, and trust that there are no bugs in any of the FortiNet software, no hackers, etc.

 

In the old-old days we would use ethernet cables an an unmanaged switch to accomplish this.  In more recent times we would create a "virtual LAN" (or "VLAN" for short) to accomplish this.  Apparently this is impossible with the FortiNet setup?

 

Chris

brycemd

Just leave the IP as default. 0.0.0.0/0.0.0.0

 

Edit:

I guess we should clarify if we are talking from the fortigate/managed fortiswitch perspective or from a standalone fortiswitch perspective.

 

From a standalone fortiswitch perspective, you do not need to specifiy any IP for any VLAN, it doesn't even ask unless you are creating a management interface. Same as really any other switch out there.

 

From a FortiGate/managed fortiswitch perspective you can set the IP to 0.0.0.0/0.0.0.0 to accomplish the same thing.

ChrisStankevitz

Bryce: thank you.  I was able to edit the VLAN interface and set the ip to 0.0.0.0/0.0.0.0.  I believe that was the default, but when I created the "VLAN" originally and left the default I was told "invalid ip" which made me think I had to set it to something.

 

And yes, this is a FortiGate FortiManaged FortiSwitch

 

Thanks again,

 

Chris

bmattos

Hi there. I don't know if this will help you or not. I have a L2/L3 Fortiswitch. For some vlans it works as a L3 switch, but L3 for others. For L3 I configured the vlan in System  --> Network --> Interface  --> Vlan, whre I'm asked to enter an IP apddress. For L2 vlans I configured in Switch --> VLAN --> Add VLAN, where I'm not asked to enter an IP address. After that I just configured my port according to my needs: tagged vlans, native vlans and so on. It works perfect, at least by now. I hope this will help you. Greetings.

Labels
Top Kudoed Authors