Hot!fortigate 60d access vlan port

Author
o.previti
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2021/01/12 01:44:48
  • Status: offline
2021/01/12 02:38:11 (permalink)
0

fortigate 60d access vlan port

i have un fortigate 60d , i removed the cisco switch to manage everything from the firewall. on the cisco switch I had ports in access mode, is it possible to have the same configuration on the firewall ports?
#1

10 Replies Related Threads

    isamt
    Bronze Member
    • Total Posts : 48
    • Scores: 2
    • Reward points: 0
    • Joined: 2017/12/29 01:52:35
    • Status: offline
    Re: fortigate 60d access vlan port 2021/01/12 09:18:49 (permalink)
    0
    Fortigates operate in switch or interface mode
    In switch mode you have a single virtual interface containing all user ports so effectively acts as in access switch mode.
     
    #2
    o.previti
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2021/01/12 01:44:48
    • Status: offline
    Re: fortigate 60d access vlan port 2021/01/12 09:25:19 (permalink)
    0
    i have configurated hardware switch and free internal 
     
    [image][/image]
     
    but i can't put internals in access mode on a specific vlan like normal cisco switches. example I have a device that I cannot set the vlan but I have wired on my fortigate and not being on the vlan specification it is not reached by other devices 
    #3
    Toshi Esumi
    Expert Member
    • Total Posts : 2403
    • Scores: 233
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: fortigate 60d access vlan port 2021/01/12 09:36:08 (permalink)
    0
    Probably that's not what the OP needs. The OP probably needs to set a VLAN other than non-tagged interface but strip the vlan tag when it's assigned to one particular physical port, which can't do that with any FGTs. There is no access port concept exist in FGTs because they say "FGT is not a L2 switch". I don't think it's a good idea to replace the Cisco switch features with FGT's. I would leave the switch to handle L2 switching if your network requires "switching".
    #4
    o.previti
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2021/01/12 01:44:48
    • Status: offline
    Re: fortigate 60d access vlan port 2021/01/12 09:47:36 (permalink)
    0

    I wonder then why the hardware switch function. I'm trying
     
    edit "internal5"
    set vdom "root"
    set ip 172.25.40.254 255.255.255.0
    set allowaccess ping
    set alias "QNAP"
    set device-identification enable
    set role lan
    set type physical
    set snmp-index 20
    set vlanid 40
    next
     
    but when i try the command set vlanid 40 show error 
     
    [image][/image]
     
     
    #5
    Toshi Esumi
    Expert Member
    • Total Posts : 2403
    • Scores: 233
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: fortigate 60d access vlan port 2021/01/12 10:24:52 (permalink)
    0
    Your attached images are broken. But the hard-switch "config sys virtual-switch" is to have the same set of non-tag + VLANs on a set of multiple physical ports. Then it becomes a single port for configuration.
    #6
    Selective
    Expert Member
    • Total Posts : 2746
    • Scores: 119
    • Reward points: 0
    • Joined: 2007/07/03 10:44:56
    • Location: Gothenburg - Sweden
    • Status: offline
    Re: fortigate 60d access vlan port 2021/01/12 10:47:53 (permalink)
    0
    Only certain models support vlan switch, in other words to put an interface or groups of interfaces as "untagged vlan"
     
    First it needs to activated:
    config system global
    set virtual-switch-vlan enable
    end
     
    then it should be visible in the GUI:

     
    Then you can also create "Trunk" interfaces.
     
    It is documented here:
    New Features | FortiGate / FortiOS 6.2.0 | Fortinet Documentation Library
     
    post edited by Selective - 2021/01/12 10:50:06

    Attached Image(s)

    #7
    o.previti
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2021/01/12 01:44:48
    • Status: offline
    Re: fortigate 60d access vlan port 2021/01/12 23:52:06 (permalink)
    0

    I agree, but my boss wants certain devices to be behind firewalls and these devices must have the port in access
    #8
    o.previti
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2021/01/12 01:44:48
    • Status: offline
    Re: fortigate 60d access vlan port 2021/01/12 23:55:59 (permalink)
    0
    i don't have this screen .. i have 
     
    [image][/image]
     
    is probably versions os 
     
    [image][/image]
     
     
    it's possible upgrade ?
    #9
    Selective
    Expert Member
    • Total Posts : 2746
    • Scores: 119
    • Reward points: 0
    • Joined: 2007/07/03 10:44:56
    • Location: Gothenburg - Sweden
    • Status: offline
    Re: fortigate 60d access vlan port 2021/01/13 00:26:42 (permalink)
    0
    The 60D will not support "virtual-switch-vlan", (access mode).
     
    Reach out to the fortinet support and ask which models and OS supports the "virtual-switch-vlan". You probably need a newer/bigger model for that, I know it is working on 100E, 100F and 300E as I have configured it myself.
    #10
    o.previti
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2021/01/12 01:44:48
    • Status: offline
    Re: fortigate 60d access vlan port 2021/01/13 00:49:17 (permalink)
    0

    for my needs the 100E is too big .. I would like to be able to solve the problem with the 60D
    #11
    Jump to:
    © 2021 APG vNext Commercial Version 5.5