config system switch-interface
edit " internal_1234"
set member " internal1" " internal2" " internal3" " internal4"
set span enable
set vdom " root"
set span-dest-port " internal4"
set span-source-port " internal1" " internal2" " internal3"
next
end
config system interface
edit " wan1"
set vdom " root"
set mode dhcp
set allowaccess ping fgfm
set type physical
set alias " Internet - 1"
set defaultgw enable
next
edit " internal1"
set vdom " root"
next
edit " internal2"
set vdom " root"
next
edit " internal3"
set vdom " root"
next
edit " internal4"
set vdom " root"
next
edit " internal5"
set vdom " root"
set ip 192.168.20.99 255.255.255.0
set allowaccess ping https ssh http fgfm
set type physical
set alias " InternalNetwork - GUEST"
next
edit " internal_1234"
set vdom " root"
set ip 192.168.10.99 255.255.255.0
set allowaccess ping https ssh http fgfm
set type switch
set alias " InternalNetwork - Private"
next
end
Thanks for sharing config. So I'm in same boat and trying to capture multiple ports in fortigate 200 D to 1 port as span. Above config looks like its possible.
Cheers
Hi did you manage to fix? I have a similar problem trying to get 4 ports to mirror to another port that has a DarkTrace Probe on it.
Looks to me like this part should work for basic wan1 mirroring, however I'm unable to add wan1 to the members, or select as a source:
config system switch-interface edit "mirror" set member port5 wan1 set span enable set vdom root set span-dest-port port5 set span-source-port wan1 end
I get an error saying that wan1 is not part of the dataset.
| User | Count |
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.