Hello,
I would like to know the difference between the internal ports and DMZ/WAN ports on the FortiGate 60E.
Is it possible to create multiple VLANs on one internal port or it's only possible on DMZ/WAN ports ?
See this picture for exemple : [link]https://i.imgur.com/NjusR2x.png[/link]
Regards.
Solved! Go to Solution.
physically there is no difference - they're all ports. The difference since FortiOS 5.4.x is the role that is set for the interface but you can change that to unknown or lan if needed ;)
So you could use any port (except modem or console of course) for anything networking.
You can create multiple vlans on any port (depending on the role it is set to - you might have to change this to enable that.
Generally: you could use all network ports on a FGT for your purposes und you can attach mulitiple vlans to any of them.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
be carefull with FortiGate above 200E, management ports are not attached to NP which means that the performances are not the same
One important difference: those internalX ports are controlled by switch hardware, and you can put them in under one hard-switch (config sys virtual-switch) like the default internal interface. While DMZ/WAN ports are not switch ports. If you want to combine between them, you need to use a soft-switch (config sys switch-interface).
There is obvious performance difference between hard and soft-switch. There were some discussion about it for FG60D in this forum in the past. 60E is a direct successor of 60D, inheriting the same architecture.
physically there is no difference - they're all ports. The difference since FortiOS 5.4.x is the role that is set for the interface but you can change that to unknown or lan if needed ;)
So you could use any port (except modem or console of course) for anything networking.
You can create multiple vlans on any port (depending on the role it is set to - you might have to change this to enable that.
Generally: you could use all network ports on a FGT for your purposes und you can attach mulitiple vlans to any of them.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Thank you for your help.
be carefull with FortiGate above 200E, management ports are not attached to NP which means that the performances are not the same
One important difference: those internalX ports are controlled by switch hardware, and you can put them in under one hard-switch (config sys virtual-switch) like the default internal interface. While DMZ/WAN ports are not switch ports. If you want to combine between them, you need to use a soft-switch (config sys switch-interface).
There is obvious performance difference between hard and soft-switch. There were some discussion about it for FG60D in this forum in the past. 60E is a direct successor of 60D, inheriting the same architecture.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.