Created on ‎08-06-2024 09:24 AM Edited on ‎08-06-2024 09:25 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VLAN ID, VLAN protocol, or physical interface cannot be changed once a VLAN has been created.
LAB_FW_A (root) # config system interface
LAB_FW_A (interface) # edit "port1.2"
LAB_FW_A (port1.2) # set vlanid 66
LAB_FW_A (port1.2) # end
VLAN ID, VLAN protocol, or physical interface cannot be changed once a VLAN has been created.
object set operator error, -522 discard the setting
Command fail. Return code -522
LAB_FW_A (root) #
LAB_FW_A (root) # Timeout
VLAN ID, VLAN protocol, or physical interface cannot be changed once a VLAN has been created.
But Why ?
I have a VM I'm playing around with in the lab, but why can these things not be changed?
it's a networking product; I'm lost as to the logic here.
Is it a licence issue because I am just about to relicense this but as it stands, I cannot change the interface to get web/ ssh access so catch 22/.
Simon
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is not license related.
You need to delete the interface and recreate it again. Even the name can't be changed.
This can be counter intuitive but it is designed like that, probably because there is a strong bond between the kernel and these interface parameters.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, I'm new to FortiGate but have 30 years in networking. This is the first time I have met a product where the interface parameters could not be changed. really wacky. I will try to delete the interface and re-add, thanks for your time.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Simon
Let me correct myself.
I have FortiOS 6.2.16 and that's on what I tested the behavior and I confirm the VLAN ID can't be changed on this version. Other parameters you mentioned also can't be changed.
But @Cayazo and @rishab444 are right if FortiOS is 7.
In fact I tested this morning on 7.0.15 and I confirm the VLAN ID can be changed from the GUI with a king of quick wizard.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for this; I do find this odd. I'm used to products like Junipers SRX, where changing an interface is a non-issue; I also do not recall this on a Palo Alto.
But all products have their personality :) . I'm currently using 7.4.0 to match what I have in a customer environment.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @Simon_Bingham ,
You are still allowed to change the vlan ID as seen in attached screenshot.
Galileo-kvm50 (Testvlan) # show
config system interface
edit "Testvlan"
set vdom "root"
set device-identification enable
set role lan
set snmp-index 19
set interface "port4"
set vlanid 100
next
end
Galileo-kvm50 (Testvlan) # set vlanid
vlanid Enter an integer value from <1> to <4094>.
Galileo-kvm50 (Testvlan) # set vlanid 101
Galileo-kvm50 (Testvlan) # sh
config system interface
edit "Testvlan"
set vdom "root"
set device-identification enable
set role lan
set snmp-index 19
set interface "port4"
set vlanid 101
next
end
But you won't be able to change the interface This is for a reason as with with each interface change, it would impact the ARP table and shouldn't cause a conflict.
R.S
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Simon_Bingham
I'm able to re-create your error message:
LAB_FGT (interface) # edit port1.2
LAB_FGT (port1.2) # set vlanid 66
LAB_FGT (port1.2) # end
VLAN ID, VLAN protocol, or physical interface cannot be changed once a VLAN has been created.
object set operator error, -522 discard the setting
Command fail. Return code -522
The reason is that it has already been referenced in some other configuration. If you go to 'Network > Interfaces > port1.2' at the right, you'll find the references. From the CLI you'll have to manually remove the references in order to edit or delete the interface. This is the reason for adding a wizard since version 7.0:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Edit-VLAN-ID-of-a-VLAN-interface/ta-p/2152...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thankyou.
data:image/s3,"s3://crabby-images/8b625/8b62515daeb8ad3955907127c0d29638cfe9679b" alt=""