Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
antoniocerasuolo
New Contributor III

fortiwifi 40F/ how to delete a port form the hardware switch LAN to set as a solo software switchLAN

Hi,

 

my lan hardware switch interface has 3 ports lan1,lan2,lan3.-> lan

 

these 3 ports are part of the main "internal lan"

 

how do i take lan1 out of the lan hardware switch and create a second hardware switch lets say lan_2 containing only the port lan1?

 

in this fashion i would then add lan_2 to a new internal interface lets say internal_2 ?

 

how can all of this be done? it seems impossible to find where to topke out lan1 from the hardware switch.

 

any help would be appreciated.

 

ciao,

Antonio

 

30 REPLIES 30
antoniocerasuolo

thank you!!!!!!

worked perfectly!!! exactly what i was looking for

for some reason seems that i'm unable to delete any ssid? any ideas why?

 

 

funkylicious

most likely because they are used/referenced.

you have a column that says Ref. and need to be 0 or 1 and then the Delete button will become visible.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Unable-to-delete-SSID/ta-p/232445 

"jack of all trades, master of none"
"jack of all trades, master of none"
antoniocerasuolo

perfect done!!

thanks again !!!!!!!!

 

really really appreciate fortinet and your help!

antoniocerasuolo

you have been such a great help , maybe I'll ask you one more question:

 

i have implemented a proxy based policy in order to have Data leak prevention , I have solved many problems but the biggest one is that there are many denied DNS requests to fortiguard servers.

 

any idea how to solve this one also?

funkylicious

can you share the exact logs that you see ?

"jack of all trades, master of none"
"jack of all trades, master of none"
antoniocerasuolo

sure what is the comand to get the logs?

 

funkylicious

I guess you saw them in the GUI, a screenshot of those would be helpful.

Otherwise, this would be the alternative from CLI, https://community.fortinet.com/t5/FortiGate/Technical-Tip-Displaying-logs-via-FortiGate-s-CLI/ta-p/1... 

"jack of all trades, master of none"
"jack of all trades, master of none"
antoniocerasuolo

i downloaded the log file but how can i upload here?

antoniocerasuolo

here is the screen shot

Immagine3.png

funkylicious

oh well, i guess you enabled under DHCP for the wifi clients to get the DNS servers that the FortiGate has configured on it.

you would need to create a firewall policy for them to access the FortiGuard DNS servers in order to get rid of those deny logs and for them to be able to resolve anything.

under Network > DNS you should be able to see the IPs of the FortiGuard DNS servers and allow access to them or add as a ISDB (Fortinet-FortiGuard object ) as destination

 

as per this example for DNS server is the option that i'm talking about for your wifi clients

DHCP.JPG

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors