Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
holdenk
New Contributor

Routing traffic to a tagged interface

Hey Fortinet forums,

 

I have been trying to do the following in a lab and have not had any luck.  Is this even possible to do without the use of VDOMS and keeping the Fortigate in a NAT/Route Mode?

 

Basically I have a Fortigate 60E connected to a L2 switch.  The connection to the switch has tagged and untagged traffic on a single physical connection; with untagged traffic being the 10.10.1.0/24 network (purple line), and tagged VLAN 12 traffic on a 10.10.2.0/24 (Orange Line).  What I would like to do is route all traffic from the untagged 172.16.10.0/24 network (blue line) through VLAN 12 exclusively (purple line).  I have added VLAN 12 as a sub interface on WAN1 and made the default static route to send all traffic through it.  I am able to get a DHCP address on the untagged 10.10.1.0/24 network, but not with the 10.10.2.0/24 network.  I am currently on 5.6.4 and attempting to use the SD-WAN features.  Please see the attached network diagram.

 

Do any of you know if what I am trying to do is impossible, or what the settings might look like to make this work?

 

Thanks in advance!

1 REPLY 1
Toshi_Esumi
SuperUser
SuperUser

I'm not sure about SD-WAN part, but you base set up for 10.10.1.0/24 interface and 10.10.2.0/24 (sub)interface should get a DHCP IP from whatever the upstream DHCP server device. From FGT's view those two interfaces are separated and independent. I would check the DHCP server device (ISP's device?).

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors