question

Guenther avatar image
0 Likes"
Guenther asked

Firewalling between VLANs?

Hello together,

what is the best-current-practice way of connecting different VLANs on a FortiGate? Using a physical interface, the VLANs seems to work fine. But shouldn't it work on a "VLAN Switch" as well?

FortiGateVLAN
10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

1 Answer

·
fgdocs avatar image
1 Like"
fgdocs answered

Hi there. It really depends on the model of FortiGate you have, and how you plan to connect your devices to the VLAN.


Usually, on models that have few interfaces or network environments where many devices need to connect via an access switch(es), then connecting the switch to the FortiGate via a 802.1Q trunk port is recommended. See the following reference:

https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/402940/vlan


On the other hand, if your FortiGate has many ports that can support the number of devices, you can enable VLAN switch mode (on the supported models) like this:

https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/183531/virtual-vlan-switch

To enable VLAN switch mode in the GUI:
  1. Go to System > Settings.
  2. In the View Settings section, enable VLAN switch mode.
  3. Click Apply.


Hope this helps.

10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

Write an Answer

Hint: Notify or tag a user in this post by typing @username.

Up to 10 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

Welcome to FortiAnswers

FortiAnswers is the space dedicated to FortiSASE and FortiOS questions and suggestions.

  • Please review the Community guidelines
  • If you are a moderator, please refer to the Moderation guidelines
  • If something in the above guidelines is unclear, please post your question to the Community Feedback space or the Moderators' space