Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
simontpg
New Contributor

FortiGate 100d HA: add one more port to DMZ with same broadcast domain

Hello,

 

We have 2 units of FortiGate 100d running as active-active cluster and the DMZ port on both units are current connecting to a cisco switch.

We want to add one more switch to the DMZ to improve availability. Can i use the WAN 2 port or one of the internal port to group with the DMZ, so that they are in the same domain?

 

Now the internal ports are running in hardware switch mode, i can split one of its port from internal. Can i create one more virtual switch or hardware switch put the DMZ port and one another port as member to achieve this? It is possible?

 

Thank you

Simon

 

1 REPLY 1
Toshi_Esumi
SuperUser
SuperUser

I'm not sure if 100D is the same, but with any lower model (two digit number models) that comes with DMZ and/or WAN port, those ports are not under the same switching hardware that control other internal ports. Therefore DMZ and WAN port can't be in a hardware switch. It wouldn't show you as a possible member when you try creating a new hardswitch.  However, you can put them in a software switch under "config sys switch-interface"

http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-networking-54/Interfaces/Software%20s...

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors