Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sailordog
New Contributor

internal-switch-mode interface

I can' t get this 60B to switch to interface mode on the internal 6 port switch. Version: Fortigate-60B v4.0.3,build0106,090616 At Factory defaults and no interfaces up. FGT60B3908634271 # conf sys global FGT60B3908634271 (global) # set internal-switch-mode interface FGT60B3908634271 (global) # end Changing switch mode will reboot the system! Do you want to continue? (y/n)y Interface internal is in use attribute set operator error, -23, discard the setting Command fail. Return code -23 Then, following Knowledge Base " Changing from switch mode to interface mode' 03-25-2009 Document ID: 13902 FGT60B3908634271 # conf sys interface FGT60B3908634271 (interface) # rename internal to internal3 name " internal3" conflicts with names used by the switch interface hardware node_check_object fail! for name internal3 value parse error before ' internal3' Command fail. Return code -552 FGT60B3908634271 (interface) #
5 REPLIES 5
emnoc
Esteemed Contributor III

Youhave some type of dependencies nailed to the internal interface. Check for any firewall policies or IDS senors and try again after removing these items.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
lmuir
New Contributor

Yeah, I had grief changing my 60B. Make sure there' s no addresses defined on any interfaces. I suspect it will have the default IP address configured on the internal interface.
mhe
Contributor II

I usually download the config file, edit it with a editor (find/replace eg " internal" -> " internal1" but check each replacement!) and change the mode: set internal-switch-mode interface After restoring the config and rebooting file you' re done - you can also use this procedure if you have some existing policies etc. martin
harald21
Contributor

Hi, before enabeling interface-mode for the internal switch, you will have to edit some things: 1. Disable DNS-forwaring to internal interface 2. Delete the internal DHCP server 3. Delete the Firewall policy (internal: all --> wan1: all) that was created by the factory reset 4. Enable administrative acces to any other port (instead of the internal port), because after changing the switch mode the internal ports have no ip address assigned Sincerely Harald
Sailordog
New Contributor

Thanks, I had cleaned up everything else but I missed the dns forwarder. Works like a charm.
Labels
Top Kudoed Authors