Hi!
We are using Vlans based topology where we have vlans on distribution layer switches and few SVI lives on core switch.
We have fiber coming from our ISP provider that I want to terminate in in our distribution switch as I have 10G interface in my distribution switch.
The issue is that we have IP scheme our ISP and if I terminate the Fiber directly into our Fortigate FW then everything works but our 100E is just 1G sfp and we have one 10 G internet line.
The only way is to somehow terminate this to distribution switch to get 10G connection but I am coming up with any idea how I an design this because of the VLAN.
Any suggestion with this?
Thanks
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Terminate the ISP circuit at the 10G port on the switch and make it as an access port for a VLAN, let's say vlan 99. Then another port (GigE) on the same switch as the same access port for vlan 99 to connect to your FG100E.
Terminate the ISP circuit at the 10G port on the switch and make it as an access port for a VLAN, let's say vlan 99. Then another port (GigE) on the same switch as the same access port for vlan 99 to connect to your FG100E.
Thanks Toshi. I will try this.
Can you please tell any link which explain about the theory of such concept. I never heard or read this before.
Really want to read about it.
It's general "Layer2 switching" concept with VLANs you can find on the internet or some books like Cisco/Juniper certification, etc. If the 10G circuit constantly pumps in more than 1G FGT WAN interface can take, they would eventually overflow the buffer at the switch. But I assume the circuit's committed bandwidth isn't way over 1Gbps, and actual traffic wouldn't hit that level all the time.
Thanks. Thats I know that its layer 2. Let me think about the traffic flow and may be will come back with some question or say its done :).
Also is its possible to upgrade 100E SFP to SFP+?
Fortigate 100E has no 10G interface.
Smallest Model with 10G is 500E Series.
ok Thanks.
I was testing the topology in GNS3 just to clear my mind.
I am using CISCO layer 2 switch and assigned few interfaces to vlan 99 and then inserted a two routers and tried to ping each other but it didnt work.
Then I inserted two vpcs and connected them to interfaces that are part of vlan 99 but I am not able to ping them.
Its same kind of topoloy like you are connecting two machines to same vlan and The ISP port connected to interface part of vlan 99 and then on same switch I am connecting my firewall that is part of vlan 99.
But my toplogy is not working. I know that in layer 2 broadcast domain machines sitting in the same vlan can talk to each other and if you want them to talk to other vlan then you have to create SVI for intervlan routing.
I only got confused as ISP side switch/router/firewall doesnt know about VLAN 99 so I wanted to test to the results.
Sorry if I am missing point here.
I have attached the picture.
Thanks
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.