Hi,
Why labelled LAN ,WAN ,DMZ in fg .
When I am creating a VLAN it shows type is LAN ? . What does it mean by ?
"Normally the internal interface is configured as a single interface shared by all physical interface connections - a switch. The switch mode feature has two states - switch mode and interface mode. Switch mode is the default mode with only one interface and one address for the entire internal switch. Interface mode enables you to configure each of the internal switch physical interface connections separately. This enables you to assign different subnets and netmasks to each of the internal physical interface connections."
What is internal interface and switch mode here .
Thanks
LAN/WAN/DMZ have no real bearing on the function of the FortiGate. They simply adjust what features appear in the GUI to what are most relevant to the purpose chosen. Frankly I choose LAN for all interfaces just because the GUI is more consistent. The switch mode *does* change the function of the FortiGate massively. It seems you have the answer though that you pasted into your post. Basically interface mode means the FortiGate functions as a router. Every interface is a different segment at layers 2 and 3. Any switching you need to do will be done with a different piece of hardware connected to the FortiGate.
With switch mode the interfaces configured as a switch share the same layer 2 and 3 segment, so you can plug in different hosts that should share the same network and possibly don't need to buy a switch.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1743 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.