Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
qqh452821000
New Contributor

FortiGate use sub-vlan how to communicate with PC

Hello everyone

 

I have a question about fortigate use sub-vlan how to communicate with switch

I use EVE-LAB doing some test.

Here is my topo

 

 

and here are my switch G0/4 conf:

switchport trunk encapsulation dot1q switchport trunk native vlan 999 switchport mode trunk

 

PC1 ip address is 192.168.1.1/24

PC2 ip address is 192.168.2.1/24

 

PC1 should have been able to ping 192.168.1.254

PC2 should have been able to ping 192.168.2.254

 

But I use EVE-LAB, it is timeout . 

 

Is it something wrong with my configuration?

 

There is another question, Is it need to configure switchport trunk native vlan 999 on switch?

Does the fortigate vlan 1 have a tag?

 

Any body have any thought?

 

Best Regards,

Tim

1 Solution
Toshi_Esumi

If they're in FGT's arp table, you should be able to ping PCs from FGT. Have you tried? If this works, only other possibility is "trusthost" config in admin users is prohibiting from pinged. Include 192.168.1.0/24 and 2.0/24.

 

As I wrote first, untagged interface is the "port3" parent interface. You need to configure 1.254 on it without Vlan1 subinterface.

View solution in original post

7 REPLIES 7
Toshi_Esumi
SuperUser
SuperUser

On fortigate "VLAN1" is tagged. On Cisco Vlan1 is default native-vlan for all ports and untagged. You need to configure 192.168.1.254/24 on port3 parent interface.

Is the second vlan 999 as in the switch config or 119 as in the image?

Toshi_Esumi

Sorry, I misread "native vlan" config. Then it's up to the port config for the PC1 and PC2. Did you configure those access ports vlan 1 and 119 respectively? And verify those VLANs are included on G0/4 with show int trunk.

 

Toshi_Esumi

Or, the new VLAN subinterfaces are not configured to allow pinging (set allowaccess ping) on the FGT.

qqh452821000

Thank you for your reply.

I already allowaccess ping on fortigate. 

It had PC1 and PC2 's arp when I  clicked command "get system arp" on fortigate

But the PC just can's ping fortigate's IP.

qqh452821000

Thank you for you reply.

Do you know fortigate how to untag vlan 1's tag ?

thank you 

Toshi_Esumi

If they're in FGT's arp table, you should be able to ping PCs from FGT. Have you tried? If this works, only other possibility is "trusthost" config in admin users is prohibiting from pinged. Include 192.168.1.0/24 and 2.0/24.

 

As I wrote first, untagged interface is the "port3" parent interface. You need to configure 1.254 on it without Vlan1 subinterface.

qqh452821000

Thank you Toshi.

yeah.it is the ""trust host" prohibiting from pinged. I already fixed it.

I know how to configure untagged interface finally , I will try it later

 thank you again...

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors