Here are all changes compared to previous config.
config switch global
set access-vlan-mode legacy
set auto-fortilink-discovery disable
set auto-isl enable
snip
next
edit "port25"
set cdp-status disable
set description "To DBNET10G-03 Port 37 | inside"
set dmi-status global
set flapguard disabled
set flow-control disable
set fortilink-p2p disable
set l2-learning enabled
set lldp-profile "default-auto-isl"
set lldp-status tx-rx
set loopback disable
set max-frame-size 9216
set speed 10000full
set status up
set storm-control-mode global
next
edit "port26"
set cdp-status disable
set description "To DMZ10G-02 Port 35 | dmz"
set dmi-status global
set flapguard disabled
set flow-control disable
set fortilink-p2p disable
set l2-learning enabled
set lldp-profile "default-auto-isl"
set lldp-status tx-rx
set loopback disable
set max-frame-size 9216
set speed 10000full
set status up
set storm-control-mode global
next
edit "port27"
set cdp-status disable
set description "To DMZ10G-02 Port 37 | UAT"
set dmi-status global
set flapguard disabled
set flow-control disable
set fortilink-p2p disable
set l2-learning enabled
set lldp-profile "default-auto-isl"
set lldp-status tx-rx
set loopback disable
set max-frame-size 9216
set speed 10000full
set status up
set storm-control-mode global
next
edit "port28"
set cdp-status disable
set description "To AWS Direct Connect Vlan 2900"
set dmi-status global
set flapguard disabled
set flow-control disable
set fortilink-p2p disable
set l2-learning enabled
set lldp-profile "default-auto-isl"
set lldp-status tx-rx
set loopback disable
set max-frame-size 9216
set speed 10000full
set status up
set storm-control-mode global
next
edit "internal"
set description ''
next
end
config switch vlan
edit 35
set private-vlan disable
set lan-segment disable
set description "UAT Vlan35 Interface on FortiSwitch port 27"
set learning enable
set learning-limit 0
set rspan-mode disable
set igmp-snooping disable
set dhcp-snooping disable
set dhcp6-snooping disable
set access-vlan disable
set assignment-priority 128
unset policer
unset cos-queue
next
edit 2900
set private-vlan disable
set lan-segment disable
set description "AWS-DC-FortiSW Port 28"
set learning enable
set learning-limit 0
set rspan-mode disable
set igmp-snooping disable
set dhcp-snooping disable
set dhcp6-snooping disable
set access-vlan disable
set assignment-priority 128
unset policer
unset cos-queue
next
edit 2
set private-vlan disable
set lan-segment disable
set description "DMZ FortiSwitch port 26 using vlan 2 on switch but vlan 1"
set learning enable
set learning-limit 0
set rspan-mode disable
set igmp-snooping disable
set dhcp-snooping disable
set dhcp6-snooping disable
set access-vlan disable
set assignment-priority 128
unset policer
unset cos-queue
next
end
snip
next
edit "port25"
set description ''
set native-vlan 1
unset allowed-vlans
unset untagged-vlans
set discard-mode none
set dhcp-snooping untrusted
set dhcp-snoop-learning-limit-check disable
set dhcp-snoop-option82-trust disable
set arp-inspection-trust untrusted
set stp-state disabled
set stp-loop-protection disabled
set stp-root-guard disabled
set stp-bpdu-guard disabled
set loop-guard disabled
set edge-port enabled
set rpvst-port disabled
set ip-source-guard disable
set auto-discovery-fortilink-packet-interval 5
set private-vlan disable
set igmp-snooping-flood-reports disable
set mcast-snooping-flood-traffic disable
set packet-sampler disabled
set sflow-counter-interval 0
set snmp-index 25
config port-security
set port-security-mode none
end
config qnq
set status disable
set stp-qnq-admin enable
end
set vlan-mapping-miss-drop disable
set vlan-tpid "default"
set trust-dot1p-map ''
set trust-ip-dscp-map ''
set qos-policy "default"
set ptp-policy "default"
set ptp-status enable
set learning-limit 0
set sticky-mac disable
set log-mac-event disable
set nac disable
next
edit "port26"
set description ''
set native-vlan 2
unset allowed-vlans
unset untagged-vlans
set discard-mode none
set dhcp-snooping untrusted
set dhcp-snoop-learning-limit-check disable
set dhcp-snoop-option82-trust disable
set arp-inspection-trust untrusted
set stp-state enabled
set stp-loop-protection disabled
set stp-root-guard disabled
set stp-bpdu-guard disabled
set loop-guard disabled
set edge-port enabled
set rpvst-port disabled
set ip-source-guard disable
set auto-discovery-fortilink-packet-interval 5
set private-vlan disable
set igmp-snooping-flood-reports disable
set mcast-snooping-flood-traffic disable
set packet-sampler disabled
set sflow-counter-interval 0
set snmp-index 26
config port-security
set port-security-mode none
end
config qnq
set status disable
set stp-qnq-admin enable
end
set vlan-mapping-miss-drop disable
set vlan-tpid "default"
set trust-dot1p-map ''
set trust-ip-dscp-map ''
set qos-policy "default"
set ptp-policy "default"
set ptp-status enable
set learning-limit 0
set sticky-mac disable
set log-mac-event disable
set nac disable
next
edit "port27"
set description ''
set native-vlan 35
unset allowed-vlans
unset untagged-vlans
set discard-mode none
set dhcp-snooping untrusted
set dhcp-snoop-learning-limit-check disable
set dhcp-snoop-option82-trust disable
set arp-inspection-trust untrusted
set stp-state disabled
set stp-loop-protection disabled
set stp-root-guard disabled
set stp-bpdu-guard disabled
set loop-guard disabled
set edge-port enabled
set rpvst-port disabled
set ip-source-guard disable
set auto-discovery-fortilink-packet-interval 5
set private-vlan disable
set igmp-snooping-flood-reports disable
set mcast-snooping-flood-traffic disable
set packet-sampler disabled
set sflow-counter-interval 0
set snmp-index 27
config port-security
set port-security-mode none
end
config qnq
set status disable
set stp-qnq-admin enable
end
set vlan-mapping-miss-drop disable
set vlan-tpid "default"
set trust-dot1p-map ''
set trust-ip-dscp-map ''
set qos-policy "default"
set ptp-policy "default"
set ptp-status enable
set learning-limit 0
set sticky-mac disable
set log-mac-event disable
set nac disable
next
edit "port28"
set description ''
set native-vlan 2900
unset allowed-vlans
unset untagged-vlans
set discard-mode none
set dhcp-snooping untrusted
set dhcp-snoop-learning-limit-check disable
set dhcp-snoop-option82-trust disable
set arp-inspection-trust untrusted
set stp-state enabled
set stp-loop-protection disabled
set stp-root-guard disabled
set stp-bpdu-guard disabled
set loop-guard disabled
set edge-port enabled
set rpvst-port disabled
set ip-source-guard disable
set auto-discovery-fortilink-packet-interval 5
set private-vlan disable
set igmp-snooping-flood-reports disable
set mcast-snooping-flood-traffic disable
set packet-sampler disabled
set sflow-counter-interval 0
set snmp-index 28
config port-security
set port-security-mode none
end
config qnq
set status disable
set stp-qnq-admin enable
end
set vlan-mapping-miss-drop disable
set vlan-tpid "default"
set trust-dot1p-map ''
set trust-ip-dscp-map ''
set qos-policy "default"
set ptp-policy "default"
set ptp-status disable
set learning-limit 0
set sticky-mac disable
set log-mac-event disable
set nac disable
next
edit "internal"
set description ''
set native-vlan 1
set allowed-vlans 2,35,2900
unset untagged-vlans
set discard-mode none
set stp-state disabled
set stp-loop-protection disabled
set stp-root-guard disabled
set stp-bpdu-guard disabled
set loop-guard disabled
set edge-port enabled
set rpvst-port disabled
set auto-discovery-fortilink-packet-interval 5
set private-vlan disable
set igmp-snooping-flood-reports disable
set mcast-snooping-flood-traffic disable
set packet-sampler disabled
set sflow-counter-interval 0
set snmp-index 29
set vlan-tpid "default"
set trust-dot1p-map ''
set trust-ip-dscp-map ''
set nac disable
next
end
snip
edit "AWS-DC"
set mode static
set dhcp-relay-service disable
set ip 169.254.38.182 255.255.255.252
set allowaccess ping https ssh
set bfd disable
set bfd-desired-min-tx 250
set bfd-detect-mult 3
set bfd-required-min-rx 250
set icmp-redirect enable
set status up
set type vlan
set description ''
set alias "AWS-DC"
set vrrp-virtual-mac disable
set secondary-IP disable
set snmp-index 33
config ipv6
set ip6-address ::/0
set ip6-mode static
unset ip6-allowaccess
set autoconf disable
set ip6-unknown-mcast-to-cpu disable
set dhcp6-information-request disable
set ip6-send-adv disable
set vrrp-virtual-mac6 disable
set vrip6_link_local ::
end
set vlanid 2900
set interface "internal"
next
end
snip
config router bgp
set as 64514
set router-id 192.168.50.41
set keepalive-timer 60
set holdtime-timer 180
set always-compare-med disable
set bestpath-as-path-ignore disable
set bestpath-cmp-confed-aspath disable
set bestpath-cmp-routerid disable
set bestpath-med-confed disable
set bestpath-med-missing-as-worst disable
set client-to-client-reflection enable
set dampening disable
set deterministic-med disable
set fast-external-failover enable
set log-neighbour-changes enable
set cluster-id 0.0.0.0
set confederation-identifier 0
set default-local-preference 100
set scan-time 60
set maximum-paths-ebgp 1
set bestpath-aspath-multipath-relax disable
set maximum-paths-ibgp 1
set distance-external 20
set distance-internal 200
set distance-local 200
set ebgp-requires-policy enable
set graceful-stalepath-time 360
set route-reflector-allow-outbound-policy disable
config neighbor
edit "169.254.38.181"
set advertisement-interval 30
set allowas-in-enable disable
set allowas-in-enable-evpn disable
set allowas-in-enable6 disable
set enforce-first-as disable
unset attribute-unchanged
unset attribute-unchanged-evpn
unset attribute-unchanged6
set activate enable
set activate6 enable
set activate-evpn disable
set bfd disable
set capability-dynamic disable
set capability-orf none
set capability-orf6 none
set capability-default-originate disable
set capability-default-originate6 disable
set dont-capability-negotiate disable
set ebgp-enforce-multihop disable
set next-hop-self disable
set next-hop-self6 disable
set override-capability disable
set passive disable
set remove-private-as disable
set remove-private-as6 disable
set route-server-client disable
set route-server-client6 disable
set shutdown disable
set soft-reconfiguration disable
set soft-reconfiguration-evpn disable
set soft-reconfiguration6 disable
set as-override disable
set as-override6 disable
set strict-capability-match disable
set description ''
set distribute-list-in ''
set distribute-list-in6 ''
set distribute-list-out ''
set distribute-list-out6 ''
set filter-list-in ''
set filter-list-in6 ''
set filter-list-out ''
set filter-list-out6 ''
set interface ''
set maximum-prefix 0
set maximum-prefix6 0
set prefix-list-in ''
set prefix-list-in6 ''
set prefix-list-out ''
set prefix-list-out6 ''
set remote-as 64513
set route-map-in ''
set route-map-in-evpn ''
set route-map-in6 ''
set route-map-out ''
set route-map-out-evpn ''
set route-map-out6 ''
set send-community both
set send-community6 both
set keep-alive-timer 4294967295
set holdtime-timer 4294967295
set connect-timer 4294967295
set unsuppress-map ''
set unsuppress-map6 ''
set update-source ''
set weight 4294967295
set password "xxxxxxxx"
next
end
config redistribute "connected"
set status disable
set route-map ''
end
config redistribute "static"
set status disable
set route-map ''
end
config redistribute "ospf"
set status disable
set route-map ''
end
config redistribute "rip"
set status disable
set route-map ''
end
config redistribute "isis"
set status disable
set route-map ''
end
config redistribute6 "connected"
set status disable
set route-map ''
end
config redistribute6 "static"
set status disable
set route-map ''
end
config redistribute6 "ospf"
set status disable
set route-map ''
end
config redistribute6 "rip"
set status disable
set route-map ''
end
config redistribute6 "isis"
set status disable
set route-map ''
end
end