Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MontanaMike
Contributor

VLAN Question: Does The Physical Interface Need IP?

Simple question:  Does the physical interface need an IP when all I want to do is create and use multiple VLANs on sub-interfaces?  Those VLAN interfaces will have valid addresses but I'm not sure I need (or want) an address on the physical interface.  0.0.0.0/0.0.0.0 is fine with me...or am I missing something?

 

Thanks in advance!

-Mike

-Mike
4 REPLIES 4
Toshi_Esumi
Esteemed Contributor III

You don't need to touch. But I would remove all "allowaccess" and change the mode to static if it's DHCP, otherwise it would keep broadcasting non-tagged DHCP requests.

MontanaMike

Cool.  thanks for the info.  Is there any advantage to having the physical interface have an IP that I might miss?

-Mike

-Mike
Toshi_Esumi
Esteemed Contributor III

If you don't plan to use untagged netork. I don't see any. We use this trunk config all over the places.

emnoc
Esteemed Contributor III

Any advantage no, as far as  mode static should be  enabled but ensure it's set ip 0.0.0.0 0.0.0.0  for the configuration which is the default for all FGT btw.

 

That's all  that you need to do.

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors