Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aaans
New Contributor

VLAN

Hi there i need to pass trafic trough fiber between 2 buildings , and passing two different networks, my internal, and one for my access points.

Already created 2 vlan i have one Fortigate 60D, 1 HP layer3 Switch and on the other building one switch 1810G-8 that i divided the first 4 port to untagged on vlan1 and 5,6,7,8 untagged on vlan 2 leaving the default vlan all ports excluded(E)

Need help please....how do i configure the fortigate to receive traffic from 2 vlans? on port 4 for instance?

 

4 REPLIES 4
ede_pfau
Esteemed Contributor III

hi,

 

and welcome to the forums.

In order to use VLANs across switches you need to configure them as 'tagged'. The packets then carry a VLAN label (tag) with the VLAN ID in it. This way, the switch on the receiving side can decide to forward or discard them.

 

VLANs on a FGT are handled with VLAN ports. These are virtual ports built upon a physical port. If you look at System>Interfaces, Create New, you've got the choice to create a VLAN port. Assign a VLAN ID and an interface IP address plus network mask. Connect the switch port carrying that VLAN to the physical port the VLAN is created on.

 

VLAN ports on a FGT always are tagging VLAN ports.

 

Then create policies to allow traffic between (phys) ports and VLAN port, or VLAN port to VLAN port etc. just like between 'real' interfaces.

 

More info in the Reference Guide (docs.fortinet.com).


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
aaans
New Contributor

Here let me show u what i have:

 

 

 

 

aaans
New Contributor

Here is the rest it seems i can only upload 1 image ate a time....

ede_pfau
Esteemed Contributor III

HP switches (at this price range...) suck. My personal opinion.

From the switch images you cannot see much; some ports are tagged, some 'exclude all' - ??

For VLANs to be carried across the switch you need at least an ingress port, tagged, and an egress port, tagged. No VLAN IDs are shown, they have to match of course.

The FGT setup looks OK. You need policies, too.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors