Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
capricorn80
New Contributor II

WAN connectivity to Switch and then to Fortigate

Hi!

 

We are using Vlans based topology where we have vlans on distribution layer switches and few SVI lives on core switch.

We have fiber coming from our ISP provider that I want to terminate in in our distribution switch as I have 10G interface in my distribution switch.

 

The issue is that we have IP scheme our ISP and if I terminate the Fiber directly into our Fortigate FW then everything works but our 100E is just 1G sfp and we have one 10 G internet line. 

 

The only way is to somehow terminate this to distribution switch to get 10G connection but I am coming up with any idea how I an design this because of the VLAN.

 

Any suggestion with this?

 

Thanks 

1 Solution
Toshi_Esumi
Esteemed Contributor III

Terminate the ISP circuit at the 10G port on the switch and make it as an access port for a VLAN, let's say vlan 99. Then another port (GigE) on the same switch as the same access port for vlan 99 to connect to your FG100E.

View solution in original post

6 REPLIES 6
Toshi_Esumi
Esteemed Contributor III

Terminate the ISP circuit at the 10G port on the switch and make it as an access port for a VLAN, let's say vlan 99. Then another port (GigE) on the same switch as the same access port for vlan 99 to connect to your FG100E.

capricorn80

Thanks Toshi. I will try this.

 

Can you please tell any link which explain about the theory of such concept. I never heard or read this before.

 

Really want to read about it.

Toshi_Esumi
Esteemed Contributor III

It's general "Layer2 switching" concept with VLANs you can find on the internet or some books like Cisco/Juniper certification, etc. If the 10G circuit constantly pumps in more than 1G FGT WAN interface can take, they would eventually overflow the buffer at the switch. But I assume the circuit's committed bandwidth isn't way over 1Gbps, and actual traffic wouldn't hit that level all the time.  

capricorn80

Thanks. Thats I know that its layer 2. Let me think about the traffic flow and may be will come back with some question or say its done :).

 

Also is its possible to upgrade 100E SFP to SFP+?

TEN_IT

Fortigate 100E has no 10G interface.

Smallest Model with 10G is 500E Series.

capricorn80
New Contributor II

ok Thanks.

 

I was testing the topology in GNS3 just to clear my mind.

 

I am using CISCO layer 2 switch and assigned few interfaces to vlan 99 and then inserted a two routers and tried to ping each other but it didnt work.

 

Then I inserted two vpcs and connected them to interfaces that are part of vlan 99 but I am not able to ping them.

 

Its same kind of topoloy like you are connecting two machines to same vlan and The ISP port connected to interface part of vlan 99 and then on same switch I am connecting my firewall that is part of vlan 99.

 

But my toplogy is not working. I know that in layer 2 broadcast domain machines sitting in the same vlan can talk to each other and if you want them to talk to other vlan then you have to create SVI for intervlan routing.

 

I only got confused as ISP side switch/router/firewall doesnt know about VLAN 99 so I wanted to test to the results. 

Sorry if I am missing point here.

I have attached the picture.

 

Thanks

 

 

Labels
Top Kudoed Authors