Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Pandalist
New Contributor

New to FortiGate - Need help for LAN setup

Hello everyone

 

I am all new to Fortinet and FortiGate, though i am a quite old Networks "user"

 

Right now i am in the process of swapping a Juniper SRX100 with a Fortigate 92D and a Juniper SRX240 with a Fortigate 140D-POE (+FAP321C)

In general i find all the configuration points i wish (and can dream of) and  always amazed how easy and efficient everything is (especially coming from Cisco, Juniper and other Checkpoint products)

 

The only thing i am struggling with right now is the setup of the LANs and VLANs (i didn't think that going full VDOM was necessary)

 

I attached a quickly drawn high level concept of the network to give an idea of what i am trying to achieve

 

I am working with 3 VLANs

Green - 192.168.1.0/24 - DHCP server active

Amber - 192.168.10.0/24 - DHCP server active

Red - 192.168.100.0/24 - DHCP server active

 

Green is reserved for trusted devices (PCs, Macs, iDevices, ...)

Amber is reserved for internet facing servers and other devices reachable from Internet

Red is reserved for guest devices  (PCs, Macs, iDevices, ...)

 

The devices in Green are all with single link

The servers in Amber have all dual link in 802.3ad aggregation (other devices have a single link)

The devices in Red are all with single link

 

What i have been trying to achieve at first was to create the 3 VLANs and assign then to various ports but it seems i can assign only to 1 interface (may it be a port or Virtual Switch or VLAN Switch) Also i noticed that the 802.3ad ports are to be set as an Aggregate Interface

 

So i seem to be turning round and round on how to set a number of ports to the Green VLAN, another set of Ports to the Amber VLAN (along with a couple aggregated interfaces), a 3rd set of ports to the Red VLAN and the WiFi port to all 3 VLANs

 

I am quite sure i am just missing a detail but i cannot seem to make it all work together

 

I was hoping that some of you with way more experience than me on FortiGate could help me find the solution

 

Thank you in advance!

Andy

2 Solutions
ede_pfau

Changing the port members on the default 'internal' switch depends on hardware model and firmware version. If the FGT has an 'internal' switch you can always split it up into individual ports (except for the smallest FGTs...). In the GUI, try to create a new interface (System > Network > Interfaces) - which types do you have: VLAN always, aggregate as well, switch?

Recently on a 240D running v5.2.3, when I entered the Interface setup, I could tick off single member ports as needed from the 'internal' interface.

Now for the SSIDs...so you get each SSID on it's own VLAN. On the phys. port connected to the AP, create these VLANs and point the default route of each VLAN to the VLAN's interface IP (usually x.y.z.1). Now you can create policies to allow traffic from / to each SSID. Routing is done automatically for all directly connected networks (look at the Routing Monitor to see these).

 

As for the LACP trunks, just create them from otherwise unused phys. ports and then configure the virtual trunk port as you like (address, VLAN ID if you need, whatever). Per default, LACP will use 'slow' mode, i.e. sending BUPs every 30 seconds. I always switch that into 'fast' mode using the CLI ('conf sys int, edit myTrunk, set lacp-mode fast'). And yes, you should make sure that you're configuring LACP ('active', not 'passive' or 'static') trunks.

 

You'll definitively need the CLI Reference Guide along with the Handbook for the details :)

Ede Kernel panic: Aiee, killing interrupt handler!

View solution in original post

Ede Kernel panic: Aiee, killing interrupt handler!
Toshi_Esumi

Sorry for off topic from Pandalist's original question. But I want to ask ede_pfau or others if FortiSwitch can do like this that FortiGate can't do.

Nowadays major routers like Cisco, Juniper, etc. supports L2 switching separated from L3 routing, just like Pandalist drew in the diagram. I've kept asking the same/similar function on Fortigate to Fortinet SE/Sales but so far it's not happening.

View solution in original post

11 REPLIES 11
Toshi_Esumi

I might have spoken too early. Likely false positive. I couldn't find any possible way to configure this on FWF60D w/ 5.4.0. Sorry.

Pandalist

Hi Toshi

 

Thanks for having tested!

Right now i am a bit overwhelmed with events

I hope to try the 5.4 in the coming weeks on a FG140D I'll let you know as soon as i have had a chance to test :)

 

Best

Andy

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors