Fortinet black logo

Admin Guide (FGT-Managed)

VLAN mode and performance

Copy Link
Copy Doc ID e2c8cf6a-ac5a-11ec-9fd1-fa163e15d75b:618684
Download PDF

VLAN mode and performance

For FortiGate to FortiExtender connectivity, alternate VLAN mode is supported. It is an alternative for the default CAPWAP mode. While using the default FEX-WAN type interface, all traffic to and from the FortiGate is encapsulated in the CAPWAP data channel. In VLAN mode, traffic is sent and received on the VLAN interface. Because there is no encapsulation overhead and data traffic is processed in userspace currently, VLAN mode delivers better performance with the requirement that the VLAN interface be directly created on the port on which the FortiExtender is connected to the FortiGate. It is important to note that in VLAN mode, the FortiExtender and the FortiGate can be connected directly to each other or with a switch. In case of a switch in between, the switch should be configured to allow the configured VLANs.

VLAN mode must be explicitly enabled, as it is disabled by default on FortiGate, and that all the FEX-WAN interfaces must be deleted before VLAN mode is enabled.

config system global

set fortiextender-vlan-mode enable

end

Ensure that the VLAN interface is created based on the physical interface of your connected FortiExtender.

VLAN mode and performance

For FortiGate to FortiExtender connectivity, alternate VLAN mode is supported. It is an alternative for the default CAPWAP mode. While using the default FEX-WAN type interface, all traffic to and from the FortiGate is encapsulated in the CAPWAP data channel. In VLAN mode, traffic is sent and received on the VLAN interface. Because there is no encapsulation overhead and data traffic is processed in userspace currently, VLAN mode delivers better performance with the requirement that the VLAN interface be directly created on the port on which the FortiExtender is connected to the FortiGate. It is important to note that in VLAN mode, the FortiExtender and the FortiGate can be connected directly to each other or with a switch. In case of a switch in between, the switch should be configured to allow the configured VLANs.

VLAN mode must be explicitly enabled, as it is disabled by default on FortiGate, and that all the FEX-WAN interfaces must be deleted before VLAN mode is enabled.

config system global

set fortiextender-vlan-mode enable

end

Ensure that the VLAN interface is created based on the physical interface of your connected FortiExtender.