Hello,
We have 2 units of FortiGate 100d running as active-active cluster and the DMZ port on both units are current connecting to a cisco switch.
We want to add one more switch to the DMZ to improve availability. Can i use the WAN 2 port or one of the internal port to group with the DMZ, so that they are in the same domain?
Now the internal ports are running in hardware switch mode, i can split one of its port from internal. Can i create one more virtual switch or hardware switch put the DMZ port and one another port as member to achieve this? It is possible?
Thank you
Simon
I'm not sure if 100D is the same, but with any lower model (two digit number models) that comes with DMZ and/or WAN port, those ports are not under the same switching hardware that control other internal ports. Therefore DMZ and WAN port can't be in a hardware switch. It wouldn't show you as a possible member when you try creating a new hardswitch. However, you can put them in a software switch under "config sys switch-interface"
User | Count |
---|---|
2561 | |
1357 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.