This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VLANs on single LAN interface

Hello everybody and thank you for your support

I'm deploing a new couple of XG Firewals instead of two old UTM9 but i've found many problems on VLAN configuration.

This is my actual UTM9 configuration:

As you can see i've the ETH1 configured with 3 Vlans and everything works fine.

 

On the XG i'm trying to replicate my configuration creating 3 vlans on eth8 

My first question is: why do i have to configure an ip on the physical ifc if i'm configuring vlans on that interface?

And why the only working vlan is the one on the same subnet of the physical interface?

 

If i connect something on 172.16.100.X subnet everything works fine, but on 172.16.90.X don't work.

The only firewall rule i've created is from (zone) LAN (host) VLAN100 network; VLAN90 network ---> WAN

My network topology is very easy, just 2 FW and 2 managed switch. 

On the switches the port connected to the XG is configured in trunk mode.

 

 

I  have to use only one cable between XG and Switches as is

The XG version is SFOS 17.0.6 MR-6



This thread was automatically locked due to age.
Parents
  • Hi,

    it is not possible to configure in the current build a VLAN Interface without having a physical.

    But you can create new Zone (Called it Dummy) and configure a not existing static IP or place DHCP on it.

    XG does not support VLAN ID 1, instead you use the physical interface.

    Cheers

    __________________________________________________________________________________________________________________

  • Thanks

    the ip on static ifc is not a real problem.. 

    What about the two vlans? there is a way to let them works as i need?

Reply Children