Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tanr
Valued Contributor II

Managed FortiSwitches 3.6.7 Force untagged frames

Hi All,

 

I've got a couple FortiGates managing a few FortiSwitches now, and have some questions about edge ports.

  • With managed FortiSwitches it looks like there is no way to require untagged frames on an edge port (discard-mode all-tagged) unless I upgrade to 6.0.x and per the docs native vlan tagged frames are automatically accepted, which could possibly allow frames with two 802.1Q tags. I've changed the switch config directly through the switch CLI to set edge interfaces to have discard-mode all-tagged (it's none by default).  Is this going break something, or is it a valid solution?
  • Edge ports also still have lldp-profile default-auto-isl, which I don't want to allow.  Again, is changing this directly through switch CLI okay?[/ol]

    Thanks for any pointers.

  • 1 REPLY 1
    tanr
    Valued Contributor II

    Discovered you can change this from the GUI if you add the lldp-profile to the displayed ports list.

     

    So remaining question is how to set discard-mode all-tagged for managed FortiSwitch interfaces.

    Labels
    Top Kudoed Authors