Hi everyone,
I’m working on a FortiGate(FortiGate F100-7.6) deployment where VLANs are currently configured under a hardware switch interface. Each switch in the network is connected to the FortiGate via individual trunk links. Now, I want to migrate to a more scalable setup using aggregate (LAG) interfaces between the FortiGate and the switches.
Here’s the challenge:
I want to continue using the same VLANs (e.g., VLAN 10, 20, 30) across the network.
These VLANs are already configured and working on the FortiGate’s hardware switch interface.
I now need to connect the switches using new aggregate interfaces, but I’m not sure how to handle the VLAN configuration on the FortiGate side.
My question is:
Can I use the same VLANs (with the same IDs) on both the existing hardware switch and the new aggregate interfaces.
what's the best way to deal with this. i will have 3 switches in aggreg with the fortigate. I know the switch side configuration, only confused about the vlan config on the fortigate
FortiGate #802.3
if you create the same vlan id under a new interface/aggr it should not be a issue.
Created on 05-21-2025 06:31 AM Edited on 05-21-2025 06:38 AM
Hi @funkylicious I have already tried that but i am not able to get the connectivity. i also created policies but no result.
Created on 05-21-2025 08:24 AM Edited on 05-21-2025 08:25 AM
I don't think a VLAN ID on the hardware-switch is connected to the same VLAN ID on an interface OUTSIDE of the hardware-switch, like on an independent individual port or LAG combining those independent ports based on my experience in the past.
I think you can even configure L3 on both sides since they're separated.
You have to either do hard-cut or have L3 routing between them by changing the subnet. If you do the hard-cut while it's running, you have to remove the original VLAN, and all dependent config. It might be difficult to do. So instead, I would just change the "set interface" of the VLAN after downloading the config into a file. When you restore it with the modified config, it would reboot. Just be aware.
Also, keep the original config file handy just in case you have to revert.
Toshi
Toshi
Created on 05-22-2025 04:54 AM Edited on 05-22-2025 04:57 AM
Hi Thankyou for your reply. I tried creating the same vlan id under the aggreg interface. But i am not able to pass traffic. Even if i delete the vlans from the hardware switch(clarification-hardware switch on fortigate/not the cisco switch cisco side is already configured) and only create on 1 aggreg interfaces with IP address and on other Aggreg interfaces without IP address and with same vlan ID.
the traffic pass only between 1 aggreg interface only and the Aggreg int without IP address on the vlan doesnot get traffic
User | Count |
---|---|
2403 | |
1290 | |
778 | |
528 | |
454 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.