Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JHamilton
New Contributor

VLAN traffic switching

I' ve just converted my home office network from a competitor' s product (it was blue and had a bridge logo on it) to a FortiWifi-60D. In converting from the other network layout to the new FortiWifi, I am having trouble with my VLAN configuration. My layout has the FortiWifi connected via VLAN trunk to a distribution switch with several VLANs. The FortiWifi is configured in with " set internal-switch-mode interface" . I have the FortiWifi configured so that the VLAN trunking is working just fine to the switch, but I want to have some of the VLANs available on local internal interface ports on the FortiWifi. I have the VLAN trunk set up so that VLAN 1 is untagged, and VLANs 250-254 are tagged. The FortiWifi is configured with IP addresses 172.16.x.1, where the x is the VLAN ID. The trunk is connected internal1. I' d like to connect hosts to the other internal ports to those various VLANs, but I can' t seem to figure out how to set up a port for switching based on a VLAN tag from another port. I hope this is possible, because it was quite simple to set up with the competing product I used previously. Thanks!
11 REPLIES 11
baitken
New Contributor

I just had this exact situation come up. The client is using a voice VLAN routed at the FortiGate to the data VLAN. The FortiGate is configured with the internal1 interface on the data VLAN and an additional tagged VLAN interface for the voice VLAN. There is now a requirement to plug a host (PBX system) into the FortiGate directly on the voice VLAN and due to physical restrictions it would be difficult to plug into an access port on a switch. On my test system I have created a software switch between the voice VLAN and an unused port, which the FG did not complain about. In theory I should be able to plug a host directly into a port and it will be able to communicate through the soft switch to the voice VLAN. I will test in the next few days.
emnoc
Esteemed Contributor III

Keep us posted but I don' t think that will work as intended. The integral switch in a ROUTE-NAT mode doesn' t switch vlan across ports in the same vlans. It' s not a layer2 switch in the true sense or wording of layer2.
On my test system I have created a software switch between the voice VLAN and an unused port, which the FG did not complain about.
Can you dump the config so we can get an ideal of what you mean?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors