A real-life situation
FGT1's LAN port connects to an access switch. The company now wants a guest Wi-Fi network that is separate from staff, but there is no spare port on FGT1. The answer is a VLAN interface: the same port2 can carry the staff network untagged and the guest network tagged with VLAN 20, each with its own subnet and its own policies.
- 1. Staff: Untagged frames belong to port2 itself, 10.0.1.1/24.
- 2. Guests: Frames tagged 20 belong to the VLAN interface guest, 10.0.20.1/24.
Interface types
| Type | What it is | Use it for |
|---|---|---|
| Physical | A real port: port1, wan1, internal1… | Every connection starts here |
| VLAN | One 802.1Q VLAN ID on a parent interface | Several networks on one port to a switch trunk |
| Aggregate | Ports bundled with LACP | More bandwidth and link redundancy to a switch |
| Redundant | Ports with one active at a time | Link redundancy to switches without LACP |
| Hardware switch | Ports switched by the hardware, one IP address | Small sites plugging PCs straight into the FortiGate |
| Software switch | Interfaces bridged in software (can include Wi-Fi) | Joining interfaces the hardware can't switch together |
| Loopback | A virtual interface that is always up | Management, routing protocol IDs, VPN endpoints |
Configure a VLAN interface
config system interface
edit guest
set vdom root
set interface port2
set vlanid 20
set ip 10.0.20.1 255.255.255.0
set role lan
set allowaccess ping
next
endThe switch port facing FGT1 must be a trunk carrying VLAN 20 (and the staff network untagged, or as its own VLAN). Guests get ping only: no management access to the FortiGate from the guest network.
Give the guests addresses: DHCP server
config system dhcp server
edit 2
set interface guest
set default-gateway 10.0.20.1
set netmask 255.255.255.0
set dns-service default
config ip-range
edit 1
set start-ip 10.0.20.100
set end-ip 10.0.20.199
next
end
next
enddns-service default hands out the FortiGate's own DNS servers. Each interface can have its own DHCP server; in the GUI it is part of the interface's page.
Bundle two ports: aggregate
config system interface
edit agg1
set vdom root
set type aggregate
set member port5 port6
set lacp-mode active
set ip 10.0.5.1 255.255.255.0
next
endThe switch must bundle the same two ports with LACP. Member ports must have no IP address and no other references before they can join.
Roles and administrative access
- The role (LAN, WAN, DMZ, undefined) only changes which options the GUI shows, for example DHCP server settings on LAN interfaces. It doesn't change traffic handling.
- Administrative access (
allowaccess) lists the protocols the FortiGate answers on that interface: allow HTTPS and SSH only on trusted networks, and ping where it helps troubleshooting. - Device detection on LAN interfaces lets the FortiGate identify connected devices by MAC address, operating system and more.
Zones
config system zone
edit LAN-ZONE
set interface port2 guest
set intrazone deny
next
endPolicies can now use LAN-ZONE instead of port2 and guest separately. intrazone deny (the default) blocks traffic between the zone's own interfaces unless a policy allows it.
Zones keep a rule base short when several interfaces need the same treatment, for example ten branch VLANs that all get the same Internet access. The trade-off: you can no longer write a policy for one member interface on its own.
Why it works this way
A FortiGate writes policies between interfaces, so every separate network you want to control needs its own interface. VLAN interfaces make that cheap: one cable can carry many networks, each still a separate interface for policies and DHCP. Zones go the other way, merging interfaces when separate control isn't needed.
Common mistakes
- Creating the VLAN interface on FGT1 but leaving the switch port in access mode, so tagged frames never arrive.
- Allowing HTTPS or SSH on guest or WAN interfaces.
- Expecting two interfaces in the same zone to talk freely: intrazone traffic is denied by default.
- Trying to add a port that has an IP address or is used in a policy to an aggregate or zone.
Key takeaways
- Interfaces can be physical, VLAN, aggregate, redundant, hardware or software switch, loopback or tunnel.
- A VLAN interface needs a parent port, a VLAN ID and a matching trunk on the switch.
- allowaccess controls management access to the FortiGate; the role only changes the GUI.
- Zones group interfaces for policies; intrazone traffic is denied by default.
Check yourself
Guests on the new VLAN 20 interface get no DHCP address. FGT1's DHCP server is configured. What should you check first on the switch?
port2 and guest are both in LAN-ZONE with default settings. Can a guest reach a staff PC?
Two ports to a core switch must carry traffic together and survive one link failing. The switch supports LACP. Which interface type?