Hi there i need to pass trafic trough fiber between 2 buildings , and passing two different networks, my internal, and one for my access points.
Already created 2 vlan i have one Fortigate 60D, 1 HP layer3 Switch and on the other building one switch 1810G-8 that i divided the first 4 port to untagged on vlan1 and 5,6,7,8 untagged on vlan 2 leaving the default vlan all ports excluded(E)
Need help please....how do i configure the fortigate to receive traffic from 2 vlans? on port 4 for instance?
hi,
and welcome to the forums.
In order to use VLANs across switches you need to configure them as 'tagged'. The packets then carry a VLAN label (tag) with the VLAN ID in it. This way, the switch on the receiving side can decide to forward or discard them.
VLANs on a FGT are handled with VLAN ports. These are virtual ports built upon a physical port. If you look at System>Interfaces, Create New, you've got the choice to create a VLAN port. Assign a VLAN ID and an interface IP address plus network mask. Connect the switch port carrying that VLAN to the physical port the VLAN is created on.
VLAN ports on a FGT always are tagging VLAN ports.
Then create policies to allow traffic between (phys) ports and VLAN port, or VLAN port to VLAN port etc. just like between 'real' interfaces.
More info in the Reference Guide (docs.fortinet.com).
HP switches (at this price range...) suck. My personal opinion.
From the switch images you cannot see much; some ports are tagged, some 'exclude all' - ??
For VLANs to be carried across the switch you need at least an ingress port, tagged, and an egress port, tagged. No VLAN IDs are shown, they have to match of course.
The FGT setup looks OK. You need policies, too.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.