I want to create a VLAN. I do not want to create a VLAN Interface. I do not want routing/gateway capability. I do not want the FortiSwitch/FortiGate to take an IP address on this VLAN.
Is this possible? I'm beginning to think that in the FortiWorld it is impossible to create a Layer2-only entity.
Thank you,
Chris
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Just leave the IP as default. 0.0.0.0/0.0.0.0
Edit:
I guess we should clarify if we are talking from the fortigate/managed fortiswitch perspective or from a standalone fortiswitch perspective.
From a standalone fortiswitch perspective, you do not need to specifiy any IP for any VLAN, it doesn't even ask unless you are creating a management interface. Same as really any other switch out there.
From a FortiGate/managed fortiswitch perspective you can set the IP to 0.0.0.0/0.0.0.0 to accomplish the same thing.
No it's not possible in a std L3 firewall configuration. You need a layer3 address. What are you trying to do specifically so we can understand this request?
Ken Felix
PCNSE
NSE
StrongSwan
Hi Ken,
Thank you for your reply.
I don't want anything talking on the LAN, except some devices that I have identified. I don't want the fortinet equipment even consuming one of the precious IP addresses on the subnet. I want a guarantee that nothing else can transmit on the LAN -- I want routing disabled. I don't want the firewall to even have an opportunity to allow someone else to talk on this LAN, even if misconfigured. If the switch must have an IP address on the LAN, then I have no guarantee about any of this and instead have to trust my understanding of FortiNet, trust my configuration, and trust that there are no bugs in any of the FortiNet software, no hackers, etc.
In the old-old days we would use ethernet cables an an unmanaged switch to accomplish this. In more recent times we would create a "virtual LAN" (or "VLAN" for short) to accomplish this. Apparently this is impossible with the FortiNet setup?
Chris
Just leave the IP as default. 0.0.0.0/0.0.0.0
Edit:
I guess we should clarify if we are talking from the fortigate/managed fortiswitch perspective or from a standalone fortiswitch perspective.
From a standalone fortiswitch perspective, you do not need to specifiy any IP for any VLAN, it doesn't even ask unless you are creating a management interface. Same as really any other switch out there.
From a FortiGate/managed fortiswitch perspective you can set the IP to 0.0.0.0/0.0.0.0 to accomplish the same thing.
Bryce: thank you. I was able to edit the VLAN interface and set the ip to 0.0.0.0/0.0.0.0. I believe that was the default, but when I created the "VLAN" originally and left the default I was told "invalid ip" which made me think I had to set it to something.
And yes, this is a FortiGate FortiManaged FortiSwitch
Thanks again,
Chris
Hi there. I don't know if this will help you or not. I have a L2/L3 Fortiswitch. For some vlans it works as a L3 switch, but L3 for others. For L3 I configured the vlan in System --> Network --> Interface --> Vlan, whre I'm asked to enter an IP apddress. For L2 vlans I configured in Switch --> VLAN --> Add VLAN, where I'm not asked to enter an IP address. After that I just configured my port according to my needs: tagged vlans, native vlans and so on. It works perfect, at least by now. I hope this will help you. Greetings.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.