Course menu

Module 1: Getting StartedLesson 1.4 (4 of 5 in this module)4 of 18 in the FortiGate Administrator course

Interfaces, VLANs and zones

Physical ports, VLAN interfaces, aggregates and switches, interface roles and administrative access, DHCP servers and zones.

Intermediate · 13 min read

What you will learn

After this lesson, you can create VLAN, aggregate and switch interfaces on a FortiGate, choose administrative access and roles, run a DHCP server, and group interfaces into zones.

  • Interface settings
  • VLAN interfaces
  • Aggregate (LACP)
  • Zones

A FortiGate interface is anything traffic can enter or leave by: a physical port, a VLAN interface on a port, a bundle of ports (aggregate or redundant), a group of ports acting as a switch, a loopback or a VPN tunnel. Each has its own IP address in NAT mode, and firewall policies are written between interfaces (or zones that group them).

In simple terms: Interfaces are the FortiGate's doors. Some are real sockets, some are virtual doors that share a socket, and zones group several doors under one name.

A real-life situation

FGT1's LAN port connects to an access switch. The company now wants a guest Wi-Fi network that is separate from staff, but there is no spare port on FGT1. The answer is a VLAN interface: the same port2 can carry the staff network untagged and the guest network tagged with VLAN 20, each with its own subnet and its own policies.

port2: untagged + VLAN 20 taggedFGT1port2 = trunkSW1access switchStaff PCuntagged · 10.0.1.0/24Guest laptopVLAN 20 · 10.0.20.0/24
  1. 1. Staff: Untagged frames belong to port2 itself, 10.0.1.1/24.
  2. 2. Guests: Frames tagged 20 belong to the VLAN interface guest, 10.0.20.1/24.

Interface types

TypeWhat it isUse it for
PhysicalA real port: port1, wan1, internal1…Every connection starts here
VLANOne 802.1Q VLAN ID on a parent interfaceSeveral networks on one port to a switch trunk
AggregatePorts bundled with LACPMore bandwidth and link redundancy to a switch
RedundantPorts with one active at a timeLink redundancy to switches without LACP
Hardware switchPorts switched by the hardware, one IP addressSmall sites plugging PCs straight into the FortiGate
Software switchInterfaces bridged in software (can include Wi-Fi)Joining interfaces the hardware can't switch together
LoopbackA virtual interface that is always upManagement, routing protocol IDs, VPN endpoints

Configure a VLAN interface

config system interface edit guest set vdom root set interface port2 set vlanid 20 set ip 10.0.20.1 255.255.255.0 set role lan set allowaccess ping next end

The switch port facing FGT1 must be a trunk carrying VLAN 20 (and the staff network untagged, or as its own VLAN). Guests get ping only: no management access to the FortiGate from the guest network.

Give the guests addresses: DHCP server

config system dhcp server edit 2 set interface guest set default-gateway 10.0.20.1 set netmask 255.255.255.0 set dns-service default config ip-range edit 1 set start-ip 10.0.20.100 set end-ip 10.0.20.199 next end next end

dns-service default hands out the FortiGate's own DNS servers. Each interface can have its own DHCP server; in the GUI it is part of the interface's page.

Bundle two ports: aggregate

config system interface edit agg1 set vdom root set type aggregate set member port5 port6 set lacp-mode active set ip 10.0.5.1 255.255.255.0 next end

The switch must bundle the same two ports with LACP. Member ports must have no IP address and no other references before they can join.

Roles and administrative access

  • The role (LAN, WAN, DMZ, undefined) only changes which options the GUI shows, for example DHCP server settings on LAN interfaces. It doesn't change traffic handling.
  • Administrative access (allowaccess) lists the protocols the FortiGate answers on that interface: allow HTTPS and SSH only on trusted networks, and ping where it helps troubleshooting.
  • Device detection on LAN interfaces lets the FortiGate identify connected devices by MAC address, operating system and more.

Zones

config system zone edit LAN-ZONE set interface port2 guest set intrazone deny next end

Policies can now use LAN-ZONE instead of port2 and guest separately. intrazone deny (the default) blocks traffic between the zone's own interfaces unless a policy allows it.

Zones keep a rule base short when several interfaces need the same treatment, for example ten branch VLANs that all get the same Internet access. The trade-off: you can no longer write a policy for one member interface on its own.

Why it works this way

A FortiGate writes policies between interfaces, so every separate network you want to control needs its own interface. VLAN interfaces make that cheap: one cable can carry many networks, each still a separate interface for policies and DHCP. Zones go the other way, merging interfaces when separate control isn't needed.

Common mistakes

  • Creating the VLAN interface on FGT1 but leaving the switch port in access mode, so tagged frames never arrive.
  • Allowing HTTPS or SSH on guest or WAN interfaces.
  • Expecting two interfaces in the same zone to talk freely: intrazone traffic is denied by default.
  • Trying to add a port that has an IP address or is used in a policy to an aggregate or zone.

Key takeaways

✅ Key takeaways
  • Interfaces can be physical, VLAN, aggregate, redundant, hardware or software switch, loopback or tunnel.
  • A VLAN interface needs a parent port, a VLAN ID and a matching trunk on the switch.
  • allowaccess controls management access to the FortiGate; the role only changes the GUI.
  • Zones group interfaces for policies; intrazone traffic is denied by default.

Check yourself

Predict · scenario 1

Guests on the new VLAN 20 interface get no DHCP address. FGT1's DHCP server is configured. What should you check first on the switch?

Predict · scenario 2

port2 and guest are both in LAN-ZONE with default settings. Can a guest reach a staff PC?

Predict · scenario 3

Two ports to a core switch must carry traffic together and survive one link failing. The switch supports LACP. Which interface type?

FAQ

Do hosts in the same zone talk to each other through the FortiGate?
Only if intrazone traffic is allowed. By default a zone blocks traffic between its own interfaces (intrazone deny); set intrazone allow, or write a policy from the zone to itself.
Why can't I add port3 to a zone?
An interface that is already used directly in a policy, route or other object can't join a zone. Remove those references first, then use the zone in their place.