Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BusinessUser
Contributor

How To Configure "Hardware Switch" As Vlan with "Access Port"

The fortigate switch has multiple ports in the "hardware switch".

I assume that it is a switch virtual interface.

I read that it is a trunk port by default.

How do I change these settings so that it is an access port for the 2 interfaces instead? 

13 REPLIES 13
RachelGomez123
Contributor

To configure a hardware switch as a VLAN with an access port, you can follow these general steps:

Identify the VLANs you want to create: Determine the number of VLANs you need and their respective VLAN IDs.

Configure the switch ports: Assign the access port to the VLAN you want. You can do this using the switch's command-line interface (CLI) or web-based interface.

Configure the VLANs: Define the VLANs you want to create on the switch. You can do this using the switch's CLI or web-based interface.

Assign ports to the VLANs: Assign the access ports to the appropriate VLANs using the switch's CLI or web-based interface.

 

Regards,

Rachel Gomez

BusinessUser

Will the VLANs be able to route to the outside WAN interface?

 

Also I read the documentation but I cant tell the difference between hardware switch and software switch. 

gfleming

There is no functional difference between a hardware switch and a software switch.

 

A hardware switch is a collection of ports which are physically bound by a switching fabric on the firewall. This allows the ports to be bridged together and forward traffic with no impact on the CPU.

 

A software switch is a bridge that allows any and all ports and port types to be bridged together in software. This results in a high load on the CPU.

Cheers,
Graham
sw2090
Honored Contributor

that is what you would do on a Hardware switch. The FortiGate Hardwareswitch does not support this.

You can attach a virtual vlan interface to the switch interface only. This means traffic coming in on any port that is member of the switch and is tagged with that vid will hit the vlan-interface and vice versa. Also FortiOS does not know "untagged" (i.e. if no or no known vid tag it with that one).

You cannot set that per port on a hardware switch on a FortiGate.

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors