- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiSwitch Intervlan Routing
Hi
I have pair of FGT connected to two core switches using fortilink with multiple access switches hanging out of the core switches. We have multiple VLANs configured on the fabric which work through FW. However there is a requirement to create 2 VLANs for which intervlan traffic should work through fortiswitces - basically want to bypass FGT for 2 specific VLANs.
We want to use FGT for intervlan routing between VLAN 10 and VLAN20.
However want to bypass FGT for VLAN 40 and VLAN50 and want to do intervlan routing using Core Switches.
Any idea how this can be achieved ?
- Labels:
-
FortiGate
-
FortiSwitch
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This cannot be achieved if the Core Switches are managed using FortiLink. You will need a standalone L3 FortiSwitch.
Graham
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Graham
Just checking this document, is it only for fortiswitches where switches are not managed by FGT ?
Configuring layer-3 routing on FortiSwitch units | FortiSwitch Manager 7.2.0 (fortinet.com)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That is documentation for the standalone FortiSwitch Manager software (it mimics a FortiGate in how it manages the FortiSwitches). Seems like as of 7.2 it can allow L3 routing on the FortiSwitch.
Perhaps that functionality is coming to FortiGate-managed FortiSwitches but AFAIK it is not possible today.
Graham
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi there,
From my understand, you want to make VLAN40 <<>>> VLAN50 can reach each other within the switch without passing through gateway(fortigate).
Any layer3 communication require gateway.
I would suggest to create a support ticket so we can verify if this feature already introduced and ready to be implemented.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi haiqal
Yes that's correct.
VLAN40 <<>>> VLAN50 -- intervlan routing within switch - no FGT involvement.
Everything else via FGT.
