Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jzeferino
Staff
Staff

Fortigate as Router on a stick, along with local access ports on one of the VLANs. Can it be done?

Hello.

 

I'm trying to set up an 81F (FortiOS 7.6.4) as router on a stick. It would be a staight forward action, however I'd like to have other interfaces set as access mode on one of the VLANs that are supposed to go through the trunk. For example, internal5 would be the trunk (VLANs 10 and 20 tagged), and internal2 and internal4 should also allow untagged access to VLAN 20.

 

I've stumbled on this article https://community.fortinet.com/t5/FortiGate/Technical-Tip-Comparing-Hardware-switches-Software-switc... and it kind of addresses the issue, if I set a virtual switch per each of the trunk's VLANs, while leaving one interface dedicated for trunk (instead of declaring dot1q entries).

 

Is there a proper way of accomplishing this? 

 

Thanks in advance for any insights, and all the best. 

1 Solution
mrsimon007
New Contributor II

Yes, it can be done. You can configure a FortiGate as a router-on-a-stick by creating sub-interfaces on a single physical port, each tied to a VLAN with its own IP. One of those VLANs can also provide local access ports by bridging the sub-interface with internal ports. This way, inter-VLAN routing is handled by the FortiGate, while users on the local access VLAN can connect directly.

View solution in original post

3 REPLIES 3
ebilcari
Staff
Staff

If I get it right, this scenario should be covered here: Example 2: LAN extension

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
jzeferino
Staff
Staff

It does, for the case that a VLAN is both made available as untagged on available Fortigate interfaces and tagged, on the designated trunk only port.

 

But how can other 802.1Q VLANs be added to that trunk only interface, in this setup (those that do not require any local access mode interfaces)?

 

Thanks 

mrsimon007
New Contributor II

Yes, it can be done. You can configure a FortiGate as a router-on-a-stick by creating sub-interfaces on a single physical port, each tied to a VLAN with its own IP. One of those VLANs can also provide local access ports by bridging the sub-interface with internal ports. This way, inter-VLAN routing is handled by the FortiGate, while users on the local access VLAN can connect directly.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors