Hi,
my lan hardware switch interface has 3 ports lan1,lan2,lan3.-> lan
these 3 ports are part of the main "internal lan"
how do i take lan1 out of the lan hardware switch and create a second hardware switch lets say lan_2 containing only the port lan1?
in this fashion i would then add lan_2 to a new internal interface lets say internal_2 ?
how can all of this be done? it seems impossible to find where to topke out lan1 from the hardware switch.
any help would be appreciated.
ciao,
Antonio
thank you!!!!!!
worked perfectly!!! exactly what i was looking for
for some reason seems that i'm unable to delete any ssid? any ideas why?
most likely because they are used/referenced.
you have a column that says Ref. and need to be 0 or 1 and then the Delete button will become visible.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Unable-to-delete-SSID/ta-p/232445
perfect done!!
thanks again !!!!!!!!
really really appreciate fortinet and your help!
Created on 01-31-2025 08:45 AM
you have been such a great help , maybe I'll ask you one more question:
i have implemented a proxy based policy in order to have Data leak prevention , I have solved many problems but the biggest one is that there are many denied DNS requests to fortiguard servers.
any idea how to solve this one also?
can you share the exact logs that you see ?
sure what is the comand to get the logs?
Created on 01-31-2025 09:02 AM Edited on 01-31-2025 09:02 AM
I guess you saw them in the GUI, a screenshot of those would be helpful.
Otherwise, this would be the alternative from CLI, https://community.fortinet.com/t5/FortiGate/Technical-Tip-Displaying-logs-via-FortiGate-s-CLI/ta-p/1...
Created on 01-31-2025 09:02 AM
i downloaded the log file but how can i upload here?
Created on 01-31-2025 09:05 AM
here is the screen shot
Created on 01-31-2025 09:08 AM Edited on 01-31-2025 09:15 AM
oh well, i guess you enabled under DHCP for the wifi clients to get the DNS servers that the FortiGate has configured on it.
you would need to create a firewall policy for them to access the FortiGuard DNS servers in order to get rid of those deny logs and for them to be able to resolve anything.
under Network > DNS you should be able to see the IPs of the FortiGuard DNS servers and allow access to them or add as a ISDB (Fortinet-FortiGuard object ) as destination
as per this example for DNS server is the option that i'm talking about for your wifi clients
User | Count |
---|---|
2559 | |
1357 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.