Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
blong
New Contributor

Fortigate + Juniper Vlan issues

First off here is a nice paint drawing of what the topology looks like http://imgur.com/omZpczi Currently The fortigate which is an 800c is running in Transparent so the routing and vlans work fine. We are switching our internet to ethernet circuit so we are wanting to switch the Nat to the fortigate to remove one device. The problem I am having when you switch to Nat/Routing mode you have to configure the vlans in the fortigate. In the picture I posted I can Make Vlan101 work it can dhcp reach the internet and ping just fine. I am having trouble making the rest of the vlans work. The way its configured now is v101 v103 are the only vlan on the trunks and the switch takes care of all the inter vlan routing. The dynamic routing is taken care of by rip as that is what the ex2200 support. Ive setup rip on the fortigate and can see all the networks. It gets the proper gateway to reach them. I can ping the gateways of the other networks from the fortigate. I can even ping a static assigned box from the fortigate although i cannot ping into it. I also cannot dhcp from the other networks. I have tried adding rules for the networks ip addresses. Adding the vlans to the interfaces they come in on. Im not sure what im missing first time ive tried to setup this fortigate this way. If i left out any important info let me know its early trying to rack my brain with everything ive done. Thanks
11 REPLIES 11
blong
New Contributor

Yes Yes Yes Yes without the fortinet in between all dhcp works fine Packet capture looks like it never getting past dhcp discover. Not sure what you mean on this ive tried allowing all from the the 101 port to port 1 which is where DHCP is located. Not sure exactly what to run to diagnose
blong
New Contributor

I thought I had already tried this but since I was doing so much probably had something else wrong somewhere. I added a rule to go from port 1 where the dhcp resides to v101 any address and dhcp started working. Thank you for your help. Definitley helped me narrow it down.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors