Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
newad01
New Contributor

VLAN Setup with a 60E & FortiSwitch 124E

First time poster... I have just got a Fortinet 60E Firewall and set this up fine and now I have to VLAN the departments off so ordered a 124E switch however I cant for the life of me get it working. I have followed the CookBook guides online but no luck so I thought I would ask the pros. Ive done VLANs before no problem on other products and know its something I am missing or doing wrong.

 

I will try and explain the issue, I setup the interlink between 60E & 124E no problem, it created VLANs, then I created the VLANs I wanted, setup a policy for internet acces for my VLANs and then assigned my VLAN as the Native VLAN on all the relevant ports. The devices would not get IP addresses or communicate with the 60E. I then tried setting up an internet policy on the VLANs the 124E seemed to setup and the computers would then get IPs but from the csw.internal6 VLAN. 

 

No idea why this is happenign when the ports are set with a Native VLAN of AdminVLAN. csw.internal6 is not set for any ports yet they seem to get IP address and info from that network.

 

Help very much appreciated as I am up against getting this fixed over the weekend.

1 REPLY 1
sw2090
Honored Contributor

Which way did you cpnnect the FGT and the Switch?

Is it using one uplink port? If so you would on the FGT have to link all the vlans to that one port (this is then called vlan trunk). Then your Switch will have to accept them all on its uplink port and you will have to set up the port s on your switch to be part of a vlan and in whch way. Traffic from the FGT comes tagged in the specific vlan and traffic to the FGT has to be tagged. 

Keep in mind that if you set any port other then the uplink one to be tagged in a vlan that would require whatever then is connected to the port will have to do vlan tagging. To avoid this set the port to be untagged. You can hava a port untagged only in one vlan.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors