Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Lapecandcie
New Contributor

Fortigate 200A configuration mode

Hello everybody,

 

I have a question about the interface mode.

Could I configure an internal port interfaced to access a specific vlan interface switch and an other one interfaced to a trunk mode interface switch?

 

Thank you in advance for your support,

 

Kind regards,

 

Christopher

7 REPLIES 7
gschmitt
Valued Contributor

Is the device in interface or switch mode?

ede_pfau

Answer: if you split the (default) "internal" switch into separate interfaces then you can use them independently, with one network per interface. Interfaces in "switch" mode behave like ONE port.

 

Does that answer your question?


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Lapecandcie

Hello,

 

Thank you for your answer,

 

@gschmitt : in the current configuration the Fortigate unit is in switch mode. The problem is that the IP address of the internal port belongs to a vlan.

 

@ede_pfau : it's to say I can have the port 1 that belongs to a specific vlan and the port2 that can be interfaced with a trunk switch interface.

 

Christopher

 

ede_pfau

As long as port1 and port2 are not selectable in a policy or in Network>Interfaces you cannot assign different networks to them (VLAN or not). They need to be separate.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Lapecandcie

OK It's what I want to know before executing actions, because I've no backup Fortigate at my disposition, even if I do a full backup of the running configuration. 

 

Lapecandcie

Ok now I have another question : I have to switch from switch mode to interface mode. I have policies in relation with the internal port. I have read that I have to remove them before. So when I will have passed in interface I have to integrate them again in the new configuration. So if I have made a full backup before doing this, I have to replace to replace into the file all "internal" references, by "internal1" or "port1" or something like that, isn't it???

Kind regards,

 

Christopher 

ede_pfau

Right. If the configuration is even medium sized it's easier to get the config file (WebGUI download), edit it and restore it to the FGT. This will enforce a reboot, so plan for some downtime.

Of course, between changing the config file and restoring it you make the switch from interface mode to port mode. Shortest way is to "exec factoryreset", remove the default policy, DHCP server and route, and do the switch ("conf sys global, set interface-switch-mode interface"). FGT will reboot then.

You will find numerous posts here for details if in doubt.

 

Unfortunately, the port names in "port mode" are hardware dependent. They might be "internal1"..."internal40" or "port1"... Too bad you don't have a spare 200A to play with.

 

edit:

From older posts users reported that the single port names are indeed "internal1" etc.

BUT...

it looks like older 200A hardware didn't support this mode. It needs to be a 200A "rev. 2" model, from end of 2007. Please look into the forum posts related to this before attempting the switch.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors