Thank you for your reply but this configuration is not directly applicable.
I'll share underneath the configuration specs from our ISP, I am trying to convert these to a complete working configuration for the Fortigate firewall:
On the WAN (1) interface underneath VLAN's need to be created with underlaying specs.
Technical details Internet:
• PPPoE via VLAN 6 (802.1q)
• PPPoE authentication PAP with a username and password (example: internet / internet).
• Maximum packet size (mtu) 1500 bytes (rfc4638) (how about mtu sizes on the WAN interface, needs to be higher 1508, 1512, ???)
• IPv4 address + DNS servers via PPPoE
• IPv6 Addresses + DNS servers (IPv6) via DHCPv6-PD request (in PPPoE)
Technical details IPtv
• Ethernet VLAN 4 (802.1q)
• Address via DHCP mandatory option60 (Vendor Class Identifier) with value: IPTV_RG.
• Specific route information via DHCP (option 55 needs value 1, 3, 28 and 121)
• Extra; Don't use DNS servers + dont use default gateway. only specific routes.
• Enable IGMP-proxy including fast-leave option mandatory for tv-signal within homenetworks (min. IGMPv2).
• Routed mode. KPN uses routed mode, no bridge mode
Remark: The tv receivers do need to be connected to the internet to be able to receive patches and updates but also be able to receive other streaming platforms; Netflix, ViaPlay etc. Needs network policy
Remark: with a lot of upstream traffic, interactive television needs to be prioritized with value 5 (802.1p)
Technical details Local network (Home network)
• IPv4 addresses (private series rfc1918) + DNS server(s) distribute via DHCP server.
• IPv6 addresses and DNS server(s) distribute (series received from prefix) via SLAAC and/or DHCPv6.
• Activate IGMP snooping function for the network ports to prevent TV signal on all ports and IGMP fast-leave to disconnect unnecessary streams like switching from channel to channel.
I'm looking for one formal configuration so we can also help others on this matter. The best I've found so far are based on the configurations as discussed here:
These configurations are almost there; things that don't seem to work are based on MTU sizes, which are the correct ones. IPv6 is an issues, works but needs attention. there is no "tunnel" option for "set type" command when creating interface "pppoe1". So probably some explanation or redisigning the config is needed.