Professional Documents
Culture Documents
Layer 2 Switching
FortiOS 7.0
© Copyright Fortinet Inc. All rights reserved. LastLast
Modified:
Modified:
Saturday,
Saturday,
August
August
19, 19,
20232023
Lesson Overview
Transparent Mode
Software Switch
Best Practices
© Fortinet Inc. All Rights Reserved. 2
Virtual Local Area Networks
Objectives
• Configure VLANs to logically divide a Layer 2 network into
multiple broadcast domains
• Describe VLANs and VLAN tagging
3
VLANs
Physical
interfaces
VLANs
Tag
Destination Source Type
Control Type Data CRC 32
MAC MAC 8100
Info
2 bytes 2 bytes
Tag
Destination Source Type
Control Type Data CRC 32
MAC MAC 8100
Info
VLAN A
VLAN B
VLAN B
VLAN A
Switch A Switch B
Transparent Mode
Software Switch
Best Practices
Objectives
• Configure FortiGate interfaces to operate as a Layer 2 switch
• Configure a virtual domain to operate in transparent mode
11
Operation Mode
• Operation mode defines how FortiGate handles traffic
• NAT mode:
• Routes according to OSI Layer 3 (IP address), as a router
• FortiGate interfaces have IP addresses associated with them
• Transparent mode:
• Forwards according to OSI Layer 2 (MAC address), as a transparent bridge
• FortiGate interfaces usually have no IP addresses
• Requires no IP address changes in the network
Clients
Ports have IP 10.0.1.0/24 subnet
addresses
internal
wan1 10.0.1.1/24
192.168.1.1/24
VLAN 101
VLAN101_dmz
VLAN 101
VLAN101_internal
VLAN 103
VLAN103_internal
dmz
internal
FortiGate in
Broadcast traffic is
transparent mode
forwarded through all with all VLANs on
VLANs same forward domain
VLAN 101
VLAN101_internal
VLAN 103
VLAN103_internal
dmz
internal
FortiGate in
transparent mode
Broadcast traffic confined
to the forward domain
with all VLANs on
different forward
domains
2. How can an administrator configure FortiGate to have four interfaces in the same
broadcast domain?
A. Create a firewall policy on each of the four interfaces
B. Configure the operation mode as transparent and use the same forward domain ID
Transparent Mode
Software Switch
Best Practices
Objectives
• Segment the Layer 2 network into multiple broadcast domains
21
Virtual Wire Pair
• Logically links two physical interfaces
• Usually one internal and one external interface
• Traffic is forwarded between these interfaces
• Incoming traffic to one interface is always forwarded out through the other interface
• No other traffic can enter or leave a virtual wire pair
• Prevents complexities such as broadcast storms, MAC flapping
wan1 port2
Virtual Wire Pair Virtual Wire Pair
port3
port1
All
All traffic
trafficconfined to the
confined to
virtual
the portwirepair
pair
Clients
10.0.1.0/24 subnet
internal
10.0.1.1/24
wan1
192.168.1.1/24 Virtual
wire pair
192.168.1.254/24
wan2 dmz
Server
192.168.2.1/24
192.168.2.254/24
Cannot assign IP
addresses to the
pair members
Selected VWPs to
include in the policy
Transparent Mode
Software Switch
Best Practices
Objectives
• Configure a software switch
29
Software Switch
• Can group multiple physical and wireless interfaces into a single virtual switch interface
• Supported only in NAT mode
• Acts like a traditional Layer 2 switch
• The interfaces:
• Share the same IP address
• Belong to the same broadcast domain
Same broadcast
192.168.1.1/24 domain
Software switch
10.0.1.1/24
interface
192.168.1.254/24
dmz
10.0.1.254/24
port1
wan1 port2 192.168.1.2/24
Wireless interface
192.168.1.3/24
FortiGate
Transparent Mode
Software Switch
Best Practices
Objectives
• Understand best practices for using Layer 2 switching on
FortiGate
35
Best Practices
• Create forwarding domains when VLANs are used and set vlanforward to disable
on all relevant physical interfaces
• The forward-domain ID can be different from the VLAN ID, but it is recommended for
troubleshooting and readability to keep them the same
• When using forwarding domains, a router is required to move traffic between the
forwarding domains
• Only interfaces from the same forwarding domains can have firewall policies between
each other
• Because STP BPDUs are not forwarded by default, use caution when inserting
FortiGate (or any other forwarding device) because this could break the spanning tree
and lead to Layer 2 loops
Transparent Mode
Software Switch
Best Practices