Hi all,
so I've gotten a training kit from my new employer, which includes a FortiGate 60F, FortiSwitch 108FPOE and a FortiAP 231F. Setting up the basic stuff was more of less painless, but now i'm struggling with some VLAN configuration issues.
Let me start of by describing the topology. The FortiGate is connected on wan1 to the internet. Port A and B are connected to the FortiSwitch through FortiLink on ports 9 and 10 (SFP RJ45).
What i'd like to achieve is create two access ports for VLAN30 on port 2 of the FortiGate and port 8 of the FortiSwitch.
Tried a million different configurations but the one that makes sense is this one:
- Get port 2 out of the internal VLAN Switch on the FortiGate.
- Create a new VLAN Switch and assign it VLAN ID 30, and use port 2 as it's member.
- Create address object matching subnet - enabled
- DHCP server - enabled
On WiFi & Switch Controller -> FortiSwitch VLANs
- Create VLAN 30
- Set IP/Netmask to 0.0.0.0/0.0.0.0
- Create address object matching subnet - disabled
- DHCP server - disabled
On WiFi & Switch Controller -> FortiSwitch Ports
- Assign VLAN30 as the Native VLAN on port 8
Policy & Objects -> Firewall Policy
- Create a policy allowing traffic from VLAN30 (upstairs) to VLAN30 (downstairs) - NAT disabled
- Create a policy allowing traffic from VLAN30 (downstairs) to VLAN30 (upstairs) - NAT disabled
I'm clearly missing something obvious here.
I basically like to create a transparent (layer2) link between port 2 of the FortiGate and port 8 of the FortiSwitch.
Anyone maybe got some pointers on how to achieve this ?
Thanks !
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Well, it took some trial and error. But i've got it working.
Initially thought that the Fortilink was also a Trunk Port, which apparently it isn't. So disconnected port B and connected it to internal5 (which i disconnected from the VLAN Switch) on the FortiGate. Enabled Ethernet Trunk on that interface and specified Allowed VLANs for port 10 (SFP RJ45) in the FortiSwitch .... and the magic ensued.
I would recommend going through these articles regarding the working of VLAN and other type of switches in fortigate
https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/183531/virtual-vlan-switch
Well, it took some trial and error. But i've got it working.
Initially thought that the Fortilink was also a Trunk Port, which apparently it isn't. So disconnected port B and connected it to internal5 (which i disconnected from the VLAN Switch) on the FortiGate. Enabled Ethernet Trunk on that interface and specified Allowed VLANs for port 10 (SFP RJ45) in the FortiSwitch .... and the magic ensued.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.