Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Arafattamim
New Contributor

Redundant Uplink

Hello Community,

We are planning to add a second uplink on our FortiGate firewall. Currently, VLAN 92 and VLAN 93 are configured as sub-interfaces under Port13.

Now we have a requirement to:

  • Add Port14 together with Port13.

  • Create a Redundant Interface (Port13 + Port14),

  • Move all existing VLAN sub-interfaces from Port13 to this new redundant interface.

My questions are:

  1. After creating the Redundant Interface, do we need to reconfigure all existing firewall policies, routes, and objects that are currently using Port13?

  2. Is there a way to migrate VLANs from Port13 to the new redundant interface without deleting/recreating all VLAN sub-interfaces manually?

  3. Does this change affect existing VPNs, static/dynamic routing, or HA configurations?

  4. Are there any best practices or recommended steps to perform this migration in production to avoid downtime?

  5. Can anyone share official Fortinet documentation or KB articles regarding redundant interface + VLAN sub-interface configuration?

  6. In GUI/CLI, which option/menu should we follow to configure this redundant interface properly?

 

1 REPLY 1
AEK
SuperUser
SuperUser

Hi Arafat

  1. Yes, but if you use interface migration or zones then you will not change any policy (using zones is good admin practice)
  2. You should be able to do it with interface migration: https://docs.fortinet.com/document/fortigate/7.0.0/new-features/885870/interface-migration-wizard
  3. Yes it does, if your VPN is built on port13. But the interface migration wizard should resolve this
  4. 5. & 6. When you say redundant, do you mean LACP? Or do you mean standalone interfaces? Or is port13 & port14 part of FortiLink?
AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors