Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
yonibar81
New Contributor

How to connect my vlan to my forigate 80c ?

hello,

i created a new vlan  on my hp switch with ip 130.39.181.181/255.255.0.0 (ports 20+21)

all my internal Network working with 172.26.30.254/255.255.255.0 (fortigate ip is 172.26.30.254)

how can i configure  that my fortigate will communicate with my vlan ?

please see my attached.

 

 

Thanks!

 

 

 

 

 

 

 

 

 

 

4 REPLIES 4
yonibar81
New Contributor

and this is my fortigate interface

MikePruett

on the port that connects the FortiGate to the Switch you need to add VLANs. So for instance, you can click internal1 and then click create new (visible on your screenshot) and vlan is an option. Define VLAN parameters as needed.

 

From there that gives the interface the ability to see the traffic.

 

Then, whatever port connects the switch to the Gate (on the switch side) needs to be configured to trunk that vlan up.

 

Another option would be to have certain ports on the switch be part of vlan x (set this vlan as those ports default vlan not a tagged vlan) and then assign a physical interface on the gate to that selection of switch ports (plug internal2 on the Gate into port on the switch that is a part of the ports that have a new default vlan) Then it can hear that accordingly (you will need to setup the interface on the Gate's IP address for this network) Probably in your interest to make the FortiGate the default gateway for the vlan so you can do cross vlan inspection as well.

Mike Pruett Fortinet GURU | Fortinet Training Videos
yonibar81

i'm sure i undestand you.

 

can i connect internal 6 (on forti) to my vlan ? and if yes, so what do i need to configure on internal 6 interface(dhcp,manuel ) ?

do i need to configure trunk frum hp switch with vlan to internal 6 ?

 

 

MikePruett

You can. If you have vlan X set as the default vlan for whatever ports then you don't have to create a vlan interface on port6. If the switch does layer 3 routing etc you would make the Gate a member of the network by just addressing it with an IP. I personally like to make the Gate the termination point for the vlan. (.1 etc ) and let the VLAN come to it.

Mike Pruett Fortinet GURU | Fortinet Training Videos
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors