Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
itsenseug
New Contributor

Fortigate -> WAN1 -> VLAN7

Dear volks,

i did the initial setup on a fortigate which is behind a VDSL2 Modem (German Provider = Vodafone VDSL). The provider require to setup a VLAN 7 (or 132) on the WAN interface to be able to connect. The only solution that i found was to add a VLAN interface on the physical interface WAN1 what is a sub-device then. For some reasons i would like to have the physikal interface to be able to have the VLAN directly (as for firewall rules it is more useful instead of working with the sub-vlan-device from my perspective).

 

So, the question is - would it be possible to setup a VLAN id on the physical interface WAN1 directly?

 

BR

Matthias

4 REPLIES 4
Toshi_Esumi
SuperUser
SuperUser

No, it's not possible with FGTs.

emnoc
Esteemed Contributor III

Hmm.... why not?

  if he's asking about a pure 802.1q tag, than yes he can  unset the WAN1 and set it with  vlan type and with a vlanid1

 

Ken Felix

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Toshi_Esumi

Unset what attribute? I looked for changing or unsetting "type" of wan1, which is physical. But I couldn't find a way to change it to something else like vlan in order to have vlanid attribute available. I'm testing it with 60E/5.6.6.

ede_pfau

From German to German: the way to go is the VLAN (sub-)interface, as with Vodafone Festnetz or Telekom triple play etc.. There is nothing peculiar with that. For documentation purposes, you can set the 'alias' which will then show up in policies.

The VLAN interface will inherit the phycial properties of the underlying WAN interface (MTU, speed, auto negotiation,...), and will respond to arp requests etc. etc. Each vendor has it's own way to handle things, and this is the way FTNT does it.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors