Hi Fortinet Community!
I've been researching around but figured I'd drop a quick post here to see what others think. Working on implementing FortiSwitches into an environment with an existing FortiGate. To be clear, the current switches are not FortiSwitches.
Layer 3 is handled by the FortiGate, and there are several VLAN sub interfaces on say the internal1 port. It looks like for this implementation, we will need to use FortiSwitch VLANs, which are bound to the FortiLink interface.
It seems like we will need to recreate the existing VLANs as FortiSwitch VLANs to utilize them in the WiFi & Switch Controller in the FortiGate as if we create them as-is I believe VLANs and subnets will conflict. I've found some clever ways to speed this process up by exporting a config backup, modifying the interface lines, and restoring. Either way this seems like it'll be intrusive and was hoping to see if anyone in the community had experience with an implementation such as this.
Thank you!
FortiBagel
Edit: I said internal1 rather than specifying that it was an aggregation port. This changes everything since aggregation interfaces do not support the interface integration feature. Seems that the only other method to quickly achieve this goal would be to backup the config, modify the lines of the sub-vlan interfaces to bind them to FortiLink, and restore the configuration. My apologies for not stating this correctly. Technically, if this was not an aggregate interface, then hbac's solution would be the correct one.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @FortiBagel,
Which firmware version are you using? You can use Integrate Interface feature. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Migrating-VLAN-interfaces-from-one-interfa...
Regards,
Hi @FortiBagel,
Which firmware version are you using? You can use Integrate Interface feature. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Migrating-VLAN-interfaces-from-one-interfa...
Regards,
Created on 03-08-2024 07:56 AM Edited on 03-08-2024 12:06 PM
Thank you for your reply! I will check that out, it looks very promising. The Gate is running v7.2.7 Build 1577, I was planning on running the latest FortiSwitch version (7.4) as I've read many say that they've always ran the latest FortiSwitch version contradictory to what I typically do with FortiGates.
Edit: I noticed that the Integrate Interface option is grayed out on the parent interface. I will be researching why this is. It is a 802.3ad Aggregate so is the destination FortiLink interface.
Edit 2: I do not believe this will work since the parent interface is a 802.3ad Aggregate interface. I found this in the article: "Note: This feature does not support turning an aggregate, software switch, redundant, zone, or SD-WAN zone interface back into a physical interface."
I don't understand. You mentioned that there are several VLAN sub interfaces under internal1 which is a physical interface. You want to start using FortiSwitch which means you'll need to use 802.3ad Aggregate (FortiLink) interface. I assume are you migrating from internal1 (physical) to FortiLink (aggregate) interface?
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.