Hello,
We are using fortiGate 60F v6.0.6. Recently we created a new Hardware Switch interface with 2 of the LAN ports as members
The role is LAN and the IP/Netmask is 0.0.0.0/0.0.0.0.
Under this hardware switch interface, we have created a VLAN, role as LAN and the IP/Netmask is 10.21.14.1/255.255.255.0
DHCP server is enable in VLAN.
Same VLAN is created in a manageable switch is tagged to the firewall VLAN. When a laptop is connected to the VLAN ports in the Switch laptop is not getting IP addess from the VLAN pool from Firewall.
See the interfaces in the firewall
Role IP/Netmask
Hardware Switch 0.0.0.0/0.0.0.0
VLAN 10.21.14.1/255.255.255.0
Firewall DHCP logs using diag sniff packet any "port 67 or port 68" 4
1264.792359 vlan in 0.0.0.0.68 -> 255.255.255.255.67: udp 300 1265.816635 vlan in 0.0.0.0.68 -> 255.255.255.255.67: udp 316 1397.432855 vlan in 0.0.0.0.68 -> 255.255.255.255.67: udp 310
Please suggest he necessary steps to get IP connected from DHCP server in firewall VLAN thru the switch.
Created on 06-02-2020 06:57 PM
Example: config system interface edit “xxxxxxx” set vdom "root" set allowaccess ping set role lan set snmp-index 54 set switch-controller-dhcp-snooping disable set interface "fortilink" set vlanid 140 next End
Reference:
Hi Barak,
He has FortiGate, not FortiSwitch..
viswanath.suri, Could you attach the "sh full" output of "config system dhcp server"
Also have you tried to connect a PC directly to the fortigate just to see if the problem is from the fortigate itself or from your manageable switch?
Thanks
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.