Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
billylo
New Contributor

Physical Lan Interface configuration

https://forum.fortinet.com/tm.aspx?m=116066

 

i have see above thread for changing switch mode to interface mode, but cant find the line  " set internal-switch-mode switch" and change that to " set internal-switch-mode interface" in Firmware Version v5.0,build0252, anyone help? thanks.

 

Current situation:

i am using FortiWIFI 90D, start with switch mode, with "internal" ip:192.168.0.x/24, now want to add a subnet 192.168.2.x/24, how can i do?

1. i try add a static route 192.168.2.x/24, with gateway 0.0.0.0, device:internal

2. create policy 

Incoming Interface:internal (LAN) Source Address:all Outgoing Interface:internal (LAN) Destination Address:all Schedule:always Service:ALL Action:ACCEPT

 

but didn't work, and i try add a router with WAN IP: 192.168.0.10, internal ip:192.168.2.1, dhcp enabled:192.168.2.100-200, all subnet pc can go internet, can ping 192.168.0.x/24 , but 192.168.0.x/24 can't ping 192.168.2.x/24 network, i want to set both 192.168.0.x/24 and 192.168.2.x/24 can communicate each other, what should i do? thanks.

1 Solution
Dave_Hall
Honored Contributor

Default settings in the config are usually not shown unless you perform something like "show full".  If this was a new fgt with little to no configuration you may be better off factory resetting the fgt and making the switch to interface mode changes from a "fresh" config.

 

If the WAN2 port is not used for anything, you could always create the 192.168.2.x subnet on that.  WAN2 is just a port label.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

View solution in original post

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
6 REPLIES 6
Dave_Hall
Honored Contributor

Default settings in the config are usually not shown unless you perform something like "show full".  If this was a new fgt with little to no configuration you may be better off factory resetting the fgt and making the switch to interface mode changes from a "fresh" config.

 

If the WAN2 port is not used for anything, you could always create the 192.168.2.x subnet on that.  WAN2 is just a port label.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Toshi_Esumi
Esteemed Contributor III

The build0252 is 5.0.5. But the interface mode was introduced with 5.2. So you have to upgrade to at least 5.2.x to be able to use interface mode.

ede_pfau

@Toshi:

The build0252 is 5.0.5. But the interface mode was introduced with 5.2. So you have to upgrade to at least 5.2.x to be able to use interface mode.
The choice between switch and interfaces was already part of FOS v4.0 back in 2009. Sorry, but take my word for it, as I am an old man.

 

Nevertheless, v5.0 is more than 5 years old and IMHO shouldn't be used on a contemporary security device anymore.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Toshi_Esumi
Esteemed Contributor III

Probably because I was dealing with 60D at that time. Maybe hardware dependent.

Dave_Hall
Honored Contributor

One thing though I like to point out, is the hard/soft switch configuration changes introduced in 5.4, should "convert" the internal interface into a breakable soft switch.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
billylo

thanks Dave , will try using WAN2.

 

thanks Toshi Esumi, so perform a firmware upgrade will auto force to convert to hardware switch mode

https://kb.fortinet.com/kb/documentLink.do?externalID=FD37588

In 5.4, there will no longer be a “set internal-switch-mode” option in global, because of the removal of Hub and Switch mode. Upon upgrade, Switch mode will be converted into Hardware Switch mode. 

anyone try, the policy will convert automatically without problem?

 

thanks ede_pfau, planning to buy a new one.

 

Labels
Top Kudoed Authors