Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sims
New Contributor III

LAN, WAN, DMZ

Hi,

Why labelled    LAN ,WAN ,DMZ  in fg .

 

When I am creating a VLAN it shows  type is LAN ? . What does it mean by ? 

 

 

"Normally the internal interface is configured as a single interface shared by all physical interface connections - a switch. The switch mode feature has two states - switch mode and interface mode. Switch mode is the default mode with only one interface and one address for the entire internal switch. Interface mode enables you to configure each of the internal switch physical interface connections separately. This enables you to assign different subnets and netmasks to each of the internal physical interface connections." 

What is internal interface and switch mode here . 

 

Thanks

1 REPLY 1
lobstercreed
Valued Contributor

LAN/WAN/DMZ have no real bearing on the function of the FortiGate.  They simply adjust what features appear in the GUI to what are most relevant to the purpose chosen.  Frankly I choose LAN for all interfaces just because the GUI is more consistent. The switch mode *does* change the function of the FortiGate massively.  It seems you have the answer though that you pasted into your post.  Basically interface mode means the FortiGate functions as a router.  Every interface is a different segment at layers 2 and 3.  Any switching you need to do will be done with a different piece of hardware connected to the FortiGate.

With switch mode the interfaces configured as a switch share the same layer 2 and 3 segment, so you can plug in different hosts that should share the same network and possibly don't need to buy a switch.

Labels
Top Kudoed Authors