Hi!
All KBs and documentation (except very early v5.0 Handbook) documents "vlanforward" field as being functional ONLY in VDOM configured in Transparent Opmode. However, this field is allowed to be set (using CLI/GUI/FortiManager) on a vlan-type subinterface whose VDOM is configured in NAT/Routed mode.
Normally, if a field is not appropriate in a particular context, FortiOS syntax disallows it to be set. So, is ability to set "vlanforward" field in subinterface with "vdom" field set to VDOM configured in NAT/Routed mode - a bug?
Thanks!
This KB:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-VLAN-forward-interface-parameter/ta-p/1930...
says only "meaningful". So I would interpret it as it's "meaningless"(antonym) if it's not TP mode and even if you configured it. I wouldn't call it a bug.
Toshi
Created on 03-12-2025 06:20 PM Edited on 03-12-2025 06:21 PM
> So I would interpret it as it's "meaningless"(antonym) if it's not TP mode and even if you configured it.
What function "vlanforward" field serves within NAT/Routed Opmode?
> I wouldn't call it a bug.
The whole point of enforcing syntax is to not allow to set fields that have no function within a context or are mutually exclusive with values set for other fields - this has always been the case with FortiOS CLI. Otherwise, all fields could be set - which, luckily, isn't so.
User | Count |
---|---|
2087 | |
1181 | |
770 | |
451 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.