Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I' d like to connect hosts to the other internal ports to those various VLANs, but I can' t seem to figure out how to set up a port for switching based on a VLAN tag from another port.You lost me on this part. Are you trying to connect the hosts to internal2 3 4 5 6 on the FWF60D? and in vlans 250-254 ? of the same 172.16.x.1 networks? If yes than I don' t think you can' t do that? those unique ports are not switching ports. If your trying to connect this to the local-distribution switch, just craft the appropiate vlans for the switch port that you want the hosts in. fwiw,a diagram would be nice and clear up what your trying to describe and express. Nice getting away from the cisco device with a bridge logo. I' m betting it' s a ASA5505 and on that model, the ports are L2-switchports but on a Fortigate they are not in that same fashion. The only other models that work this way btw are juniper SRXs. Where you can take like or un-like ports and install them into a layer2 switchport configuration and group. Why fortinet has not went that way, and other a similar feature is strange.
PCNSE
NSE
StrongSwan
Are you trying to connect the hosts to internal2 3 4 5 6 on the FWF60D? and in vlans 250-254 ? of the same 172.16.x.1 networks? If yes than I don' t think you can' t do that? those unique ports are not switching ports.Yes, I think this is what I' m trying to say. So far, from everything I' ve found, this doesn' t seem possible on the FWF60D, but I wanted to make sure. Here' s a very rough sketch of what I' m trying to do.
_________________________________ | FWF60D | --1---2---3---4---5---6---7---8-- | | | | VLAN PC on PC on PC on trunk VLAN250 VLAN251 VLAN1 | __|___________________ | Switch | ---------------------- | | | PC on PC on PC on VLAN250 VLAN251 VLAN1The VLAN trunking is working fine, and I can have PCs connected to the various FWF60D ports connected to the untagged VLAN from the VLAN trunk (VLAN1 in the diagram). Anyway, it sounds like I can' t do this, so I may have to rearrange my switches to accommodate the FortiGate' s shortcomings in this area. A small price to pay for the overall improvement over the 5505.
PCNSE
NSE
StrongSwan
You can specify which ports you want to be a part of the software switch when creating it via gui(or cli for that matter).The issue isn' t including the ports in a software switch. The problem is having frames arrive on an 802.1q VLAN trunk with VLAN tags in the header that should get switched to other ports and have the VLAN tags removed, as is appropriate for an access (vs trunk) port on the switch. This seems to be a fundamental design difference between the FortiGate and the ASA with respect to the internal switching capabilities.
Mohammad Al-Zard
Mike Pruett
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.