Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dmitriy_sosunov
New Contributor

Link Aggregation & VLAN Trunk

Guys, we please advise how FG works:)

I have experience with a lot of routers/switches but FortiGate completely confuse me;

 

Due to various reasons we had to deploy FortiGate 200D; It has two 10Gbe ports and 16 1GbE ports;

Our goal it's integrate this device into our infrastructure, the idea it's to reuse 2x10GbE ports in LACP mode and connect them to Cisco Catalyst; Technically it's not big deal, I hope but in our networks  we are using VLANs and we need to have ability to have 16x1GbE ports in access mode (assigning vlans);

 

The issue it's I was not able to setup trunk on aggregated link. Is't possible?

 

The topology:

[16x1Gbe ports] --  FG 200D == 2x10Gbe = [LACP] = Cisco Stack (2xSwitches)

 

We would like to assign access mode (vlanId) to each 1GbE port and receive tagged frames on Cisco and vise verse through 2x10Gbe links in LACP active mode.

 

Unfortunately it's single unit in our network that responsible of critical connections (IPSec) and we cannot make labs with them or any other researches; FortiGate unclear for me due to some commercial & marketing terms such as "VLAN Switch", "Virtual Link Pair", etc;

2 REPLIES 2
Toshi_Esumi
Esteemed Contributor III

First FGT doesn't have concept for access port (They say it's not "L2 switch"). All vlans you configure are tagged when the traffic hits all (trunk) ports to go outside. So all tag adding/stripping needs to happen on the Catalyst side or other outside L2 switches, and the packets have to be tagged when they hit the FGT.

sw2090
Honored Contributor

what you mean Toshi is they are untagged (i.e. the FortiGate will rewrite the vlan tag!). Due to this a vlan on a FGT is always a virtual interface ;)

So you could create a trunk to connect that to your cisco and have that be a vlan trunk on cisco's side but you will have to create a virtual interface for every vlan which is connected to that trunk on your FGT.

 

You could then create a virtual switch out of your 1 Gb Ports and then you would just need policies on your FGTs that allow traffic from there (and what is behind those) to your vlans (and back).

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors