We have a small set-up, 1 Fortigate and 7 Fortiswitches.
We have the same VLANs going to different switches and on some we have multiple VLANs.
I have a couple of questions for things I don't quite understand.
Does VLAN traffic carry over the fortilink port exclusively? My tagged VLAN port from the switch doesn't seem to be carrying much traffic.
With our limited number of switches and a lot of free ports on our firewall, we want to run a cable for each VLAN for every switch.
What is the best way to do this? I was going to do an aggregate connection but I am wondering if there is a better way.
Thanks.
VLAN traffic on a Fortigate exclusively carries over the physical interface the vlan interface is attached to. This can basically be any port on a FGT. It can also be a virtual or hw switch on a FGT. This Interface then acts like a vlan trunk port carrying all attached vlans to the next hop(s).
We for example usually have FGT=>coreswitch=>switches here. Where the coreswitch has only vlan trunk ports (one of which is the uplink to the fgt) and all following switches are attached to the coreswitch on vlan trunk ports on both sides.
Then the port configuriation on the specific switch decides wich vlan will be available there and which will not.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Hi,
VLAN traffic does not exclusively carry over the FortiLink port. Make sure the VLANs are properly configured on both the FortiGate and FortiSwitches. For connecting each VLAN to every switch, using aggregate connections (trunks) is a good approach to efficiently handle multiple VLANs over fewer physical connections. Ensure proper configuration of trunk ports on both the FortiGate and FortiSwitches for this setup.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1747 | |
1114 | |
764 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.