Configuring FortiGate LAN extension the GUI 7.4.1
This information is also available in the FortiOS 7.4 Administration Guide: |
The FortiOS GUI supports configuring the FortiGate controller and connector for the FortiGate LAN extension feature.
Example
In this example, an FG-301E is the FortiGate controller, and CAPWAP access is allowed on port3. An FG-201F is the FortiGate connector with WAN port3 connected to the FortiGate controller, and LAN port5 is connected to the client PCs.
To configure the FortiGate LAN extension:
-
On the FortiGate controller, enable the FortiExtender setting. For high-end models (1000 series and higher) and VM models, enter:
config system global set fortiextender enable end
This command is configured by default on entry-level and mid-range models (900 series and lower).
-
On the FortiGate controller, configure the port3 settings:
-
Go to Network > Interfaces and edit port3.
-
Set the Addressing mode to IPAM.
-
In this example, IPAM is not enabled yet. Click Enable IPAM. The IPAM Settings pane opens.
-
Set the Status to Enabled, enable FortiExtender LAN extensions, then click OK.
-
In the Administrative Access > IPv4 section, select Security Fabric Connection to enable CAPWAP on the interface.
-
Enable DHCP Server.
-
Click OK.
-
-
On the FortiGate connector, enable VDOMs:
-
Go to System > Settings.
-
In the System Operation Settings sections, enable Virtual Domains.
-
Click OK. You will be logged out of the device when VDOM mode is enabled.
-
-
On the FortiGate connector, enable the FortiExtender setting. For high-end models (1000 series and higher) and VM models, enter:
config system global set fortiextender enable end
This command is configured by default on entry-level and mid-range models (900 series and lower).
-
On the FortiGate connector, configure the LAN extension VDOM:
-
Go to System > VDOM and click Create New.
-
Enter a name (lan-extvdom) and set the Type to LAN Extension.
-
Click OK. The LAN Extension VDOM Created prompt appears.
-
Click Go to interface list page to assign a role (LAN or WAN) and the LAN extension VDOM.
-
-
On the FortiGate connector, edit port3:
-
Set the Role to WAN.
-
Set the Virtual domain to lan-extvdom.
-
Click OK.
-
-
On the FortiGate connector, edit port5:
-
Set the Role to LAN.
-
Set the Virtual domain to lan-extvdom.
-
Click OK.
-
-
On the FortiGate connector, select the LAN extension VDOM, and enter the IP address of the FortiGate controller:
-
Go to Network > LAN Extension.
-
Set the Access Controller (AC) address to 172.31.0.254.
-
Click Apply.
-
-
On the FortiGate controller, enable the FortiExtender feature visibility in the GUI, and authorize the FortiGate connector:
-
Go to System > Feature Visibility. In the Additional Features section, enable FortiExtender and click Apply.
-
Go to Network > FortiExtenders and select the Managed FortiExtenders tab.
-
Select the device, then right-click and select Authorization > Authorize.
-
Click OK to authorize the device.
-
-
On the FortiGate controller, configure the LAN extension interface:
-
Go to Network > Interfaces and edit the LAN extension interface.
-
Set the Addressing mode to IPAM and set When to use IPAM to Inherit IPAM auto-manage settings (default).
-
Enable DHCP Server, and configure the settings as needed (see DHCP servers and relays for more information).
-
Click OK.
-
-
On the FortiGate controller, configure the default gateway:
-
Go to Network > Static Routes and edit the default gateway settings to specify the correct internet gateway address and WAN interface.
-
Set the Gateway Address to 172.16.200.254.
-
Set the Interface to mgmt.
-
Click OK.
-
-
On the FortiGate controller, configure the firewall policy to allow traffic to pass:
-
Go to Policy & Objects > Firewall Policy and click Create New.
-
Set the Incoming Interface to the LAN extension interface.
-
Configure the other settings as needed.
-
Click OK.
-
-
On the FortiGate connector, verify that the LAN extension is connected:
-
Go to Network > LAN Extension.
-
Verify that the Status is Connected.
-