Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
wvthoog
New Contributor

Transparent VLAN between Fortigate port and FortiSwitch port

Hi all,

 

so I've gotten a training kit from my new employer, which includes a FortiGate 60F, FortiSwitch 108FPOE and a FortiAP 231F. Setting up the basic stuff was more of less painless, but now i'm struggling with some VLAN configuration issues. 

 

Let me start of by describing the topology. The FortiGate is connected on wan1 to the internet. Port A and B are connected to the FortiSwitch through FortiLink on ports 9 and 10 (SFP RJ45). 

 

What i'd like to achieve is create two access ports for VLAN30 on port 2 of the FortiGate and port 8 of the FortiSwitch. 

 

Tried a million different configurations but the one that makes sense is this one:

- Get port 2 out of the internal VLAN Switch on the FortiGate.

- Create a new VLAN Switch and assign it VLAN ID 30, and use port 2 as it's member. 

- Create address object matching subnet - enabled

- DHCP server - enabled

 

On WiFi & Switch Controller -> FortiSwitch VLANs

- Create VLAN 30 

- Set IP/Netmask to 0.0.0.0/0.0.0.0

- Create address object matching subnet - disabled

- DHCP server - disabled

 

On WiFi & Switch Controller -> FortiSwitch Ports

- Assign VLAN30 as the Native VLAN on port 8

 

Policy & Objects -> Firewall Policy

- Create a policy allowing traffic from VLAN30 (upstairs) to VLAN30 (downstairs) - NAT disabled

- Create a policy allowing traffic from VLAN30 (downstairs) to VLAN30 (upstairs) - NAT disabled

 

I'm clearly missing something obvious here. 

 

I basically like to create a transparent (layer2) link between port 2 of the FortiGate and port 8 of the FortiSwitch. 

 

Anyone maybe got some pointers on how to achieve this ?

 

Thanks !

1 Solution
wvthoog
New Contributor

Well, it took some trial and error. But i've got it working. 

 

Initially thought that the Fortilink was also a Trunk Port, which apparently it isn't. So disconnected port B and connected it to internal5 (which i disconnected from the VLAN Switch) on the FortiGate. Enabled Ethernet Trunk on that interface and specified Allowed VLANs for port 10 (SFP RJ45) in the FortiSwitch .... and the magic ensued. 

View solution in original post

2 REPLIES 2
wvthoog
New Contributor

Well, it took some trial and error. But i've got it working. 

 

Initially thought that the Fortilink was also a Trunk Port, which apparently it isn't. So disconnected port B and connected it to internal5 (which i disconnected from the VLAN Switch) on the FortiGate. Enabled Ethernet Trunk on that interface and specified Allowed VLANs for port 10 (SFP RJ45) in the FortiSwitch .... and the magic ensued. 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors