Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kliew
New Contributor

Using FortiGate for q-in-q interfaces

Does anyone know if there are plans for the FortiGate to support q-in-q like in a Cisco it would have the following

interface GigabitEthernet0/1  dot1q tunneling ethertype 0x88A8

 

and then on the sub-interface

interface GigabitEthernet0/1.101  encapsulation dot1Q 101 second-dot1q 244

 ip address <some IP>

 

Thanks in advance.

Kenneth

 

 

5 REPLIES 5
emnoc
Esteemed Contributor III

Not doable on a  FGT, if you have a need for double tag, you need to install a QinQ switch b4 the FGT.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
kliew
New Contributor

Do you think there's a chance to request a NFR (New Feature Request) for this or perhaps you might know if Fortinet has some strong design philosophy not to ever implement it ?

emnoc
Esteemed Contributor III

Send one up, worst case denied or  maybe if they get a few  ( NFRs)  they might  act upon it.

 

AFAIK, no modern firewall uses QnQ interfaces outside of  a SRX. I would think  FTNT would deploy MPLS 1st b4 getting to  QnQ but who knows.

 

But than again  Juniper is always light-years ahead in regards to these areas.

 

;)

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
kliew
New Contributor

Yeah it would be nice if people reading this can spread the word to get as many request as possible for this NFR... 

emnoc
Esteemed Contributor III

I never used QinQ dual-tag on a layer3 interface personally outside of ASR9K but i see this being issues if you wanted to  inspect and filter traffic in a layer2 hand-off like from a metroE provider and need to selectively  inspect outertag(SPtag) + innerTag(clientTag) for certain traffic

 

 Typically double-tag are terminated at a barrier device and inspection takes places south of that termination on a single tag.

 

Not even sure if a JuniperSRX could do just that but that could be a feature useful for somebody ;)

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors