Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FortiBagel
New Contributor II

FortiGate/FortiSwitch VLANs

Hi Fortinet Community!

 

I've been researching around but figured I'd drop a quick post here to see what others think. Working on implementing FortiSwitches into an environment with an existing FortiGate. To be clear, the current switches are not FortiSwitches.

 

Layer 3 is handled by the FortiGate, and there are several VLAN sub interfaces on say the internal1 port. It looks like for this implementation, we will need to use FortiSwitch VLANs, which are bound to the FortiLink interface.

 

It seems like we will need to recreate the existing VLANs as FortiSwitch VLANs to utilize them in the WiFi & Switch Controller in the FortiGate as if we create them as-is I believe VLANs and subnets will conflict. I've found some clever ways to speed this process up by exporting a config backup, modifying the interface lines, and restoring. Either way this seems like it'll be intrusive and was hoping to see if anyone in the community had experience with an implementation such as this.

 

FortiGate

FortiSwitch 

 

Thank you!

FortiBagel

 

Edit: I said internal1 rather than specifying that it was an aggregation port. This changes everything since aggregation interfaces do not support the interface integration feature. Seems that the only other method to quickly achieve this goal would be to backup the config, modify the lines of the sub-vlan interfaces to bind them to FortiLink, and restore the configuration. My apologies for not stating this correctly. Technically, if this was not an aggregate interface, then hbac's solution would be the correct one.  

 

1 Solution
hbac
Staff
Staff

Hi @FortiBagel,

 

Which firmware version are you using? You can use Integrate Interface feature. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Migrating-VLAN-interfaces-from-one-interfa...

 

Regards, 

View solution in original post

3 REPLIES 3
hbac
Staff
Staff

Hi @FortiBagel,

 

Which firmware version are you using? You can use Integrate Interface feature. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Migrating-VLAN-interfaces-from-one-interfa...

 

Regards, 

FortiBagel
New Contributor II

Thank you for your reply! I will check that out, it looks very promising. The Gate is running v7.2.7 Build 1577, I was planning on running the latest FortiSwitch version (7.4) as I've read many say that they've always ran the latest FortiSwitch version contradictory to what I typically do with FortiGates.

 

Edit: I noticed that the Integrate Interface option is grayed out on the parent interface. I will be researching why this is. It is a 802.3ad Aggregate so is the destination FortiLink interface.

 

Edit 2: I do not believe this will work since the parent interface is a 802.3ad Aggregate interface. I found this in the article: "Note: This feature does not support turning an aggregate, software switch, redundant, zone, or SD-WAN zone interface back into a physical interface."

hbac

@FortiBagel,

 

I don't understand. You mentioned that there are several VLAN sub interfaces under internal1 which is a physical interface. You want to start using FortiSwitch which means you'll need to use 802.3ad Aggregate (FortiLink) interface. I assume are you migrating from internal1 (physical) to FortiLink (aggregate) interface? 

 

Regards, 

Labels
Top Kudoed Authors