Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
player
New Contributor

Transparent mode in the middle of 802.1q trunk

Hi, the firewall is dropping all my traffic from the vlans in the trunk. any1?
player. rock the boat , dont sink the ship
player. rock the boat , dont sink the ship
8 REPLIES 8
Not applicable

Your question is vague to me but I will tell you that I have found that when running multiple VLANs through a trunk on the Fortigates in TP Mode you have to create a VDOM for each VLAN. Otherwise the sessions get jacked somehow. Somehow the session tables will see traffic from 1 VLAN going through and coming back on another which will screw the session tables up unless you VDOM the VLANS off.
player
New Contributor

suppose that i have 100 vlans in that trunk, i need to creat 100 vdoms for each one? seems a little bit funny and not real. there must be a way to deploy the FGT in the middle of the trunk in tp mode...
player. rock the boat , dont sink the ship
player. rock the boat , dont sink the ship
Not applicable

This supports my post: http://kc.fortinet.com/default.asp?id=791&Lang=1&SID=
Not applicable

hello, try to create a pair of vlan interface in each vlan id, example: vlan99-wan1 vlan id=99 physical interface=wan1 vlan99-internal vlan id=99 physical interface=internal firewall policy: vlan99-wan1 > vlan99-internal and vice versa, and so on with other different vlan id. if it' s not working, then you should use per-vlan-vdom or forward-domain per vlan interface. Regards, Fadhil
red_adair
New Contributor III

rather building VDOMs for each pair - you simply can put each VLAN-pair into a " L2 forwarding domain"
 #conf sys inter
 edit vlan_p1_100
   set fwdomain 123
 next
 edit vlan_p2_100
   set fwdomain 123
 next
 edit vlan_p1_200
   set fwdomain 987
 next
 edit clan_p2_200
   set fwdomain 987
 
check the CLI Ref guid for " set fwdomain" Broadcasts (like ARP) are only forwarded within one fwdomain (or vdom) -R.
Layard
New Contributor III

What Fortinet recommend when you have a lot of VLANS is just what red.adair said, put each VLAN in a separate L2 forwarding domain. http://docs.fortinet.com/fgt/techdocs/fortigate-vlans-vdoms.pdf Page 195
Layard Terrero
Layard Terrero
ede_pfau
SuperUser
SuperUser

d!rk' s pointer is this (it' s an old article:) " Avoiding ARP problems with VLANs in Transparent mode" http://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=10791 And this looks like your solution on a silver platter: " Technical Note : Configuring a FortiGate in Transparent mode with trunks (802.1q - VLANs) and forwarding domains" http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD30083 supplemented by " Technical Tip: Configuring a FortiGate in Transparent mode to forward traffic on VLANs and remapping VlanID using forwarding domains" http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD32877
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
rwpatterson
Valued Contributor III

I started reading this and saw names from WAYYYY back... This post is as old as dirt...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors