Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ron_mnap
New Contributor II

Is it possible to configure two different physical interface on Forti 60F to handle traffics?

My concern is: we have one physical Forti 60F that currently run the following network: 192.168.20.0/24 on port 2 connected to Cisco Switch1 and  We are looking to run 10.21.20.0/24 network on port 5 trunking with Cisco Switch2 

Once I try to connect the Fortigate port 5, it seems like, we lose internet from other network. I'm wondorring if it's something that can be done from this way. Do I need to run on different VDOM? or it could work like I did. Any help will be greatly appreciated.

11 REPLIES 11
Toshi_Esumi

Ok. "internal2" was removed from "internal" VLAN switch. So the current config under "internal2" is valid.
Since only "internal5" is the sole member of the VLAN switch, all VLANs configured on "internal" is effective only on "internal5" physical interface.

This part of config is fine.

What I would change is to change the mode of "internal" interface to "static" instead of default "dhcp" then don't set an IP. So that even if a DHCP server exist on Vlan1 broadcast domain on SW1, it won't pull any IP unintentionally.

But your "internal2" interface has 192.168.85.1/24, not 192.168.20.0/24 in the diagram. Is the subnet routed through L3 SW1?

In any case, I would sniff on internal2 (diag sniffer packet internal2 'net 192.168.20.0/24) before connecting SW2 to port5 and after, when you lose internet connectivity from the subnet if it's arriving.
If arriving, you probably need to run "flow debug" to see where it's going and why it's dropped if dropped.

Toshi

ron_mnap

Thank, you Toshi for the help, I will update you about once will be done.

Labels
Top Kudoed Authors