Fortinet white logo
Fortinet white logo

CLI Reference

config system switch-interface

config system switch-interface

Description: View LAN extension settings synced from the FortiGate. You cannot configure these settings directly on the FortiBranchSASE; you must make them through the FortiGate LAN extension profile first.

config system switch-interface
  edit <name>
    set vlan-support [enable | disable]
    config member 
      edit <name1> 
        set type [ aggregate | physical | vap]
        set port
        set vids {1-4089}
        set pvid {1-4089} 
        set security-8021x-member-mode [enable | disable]
      next
    end
    set stp [enable | disable]
    set td-mode [disable | include]
    set wired-security-mode [802.1X]
    set wired-security-group <security group ID>
  next
end

Sample syntax:

config system switch-interface
  edit lan
    set vlan-support disable
    config member
      edit port4
        set type physical
        set port port4
        set vids
        set pvid 1
        set security-8021x-member-mode enable
      next
    end
    set stp disable
    set ts-mode disable
    set wired-security-mode 802.1X
    set wired-security-group test
  next
end
Parametrer Description Type Size Default

vlan-support

Enable/disable VLAN support.

option

-

stp Spanning Tree Protocol. option - disable
Option Description
enable Enable Spanning Tree Protocol.
disable Disable Spanning Tree Protocol.

ts-mode

Read-only: Split tunnel mode.

option

-

disable

Option Description
include Enable Split tunnel mode
disable Disable Split tunnel mode.

wired-security-mode

Turn on 802.1x authentication for this interface.

option

-

wired-security-group

Names of user groups that can authenticate with the 802.1X.

option

-

dst-mac

Read-only: MAC address of the remote gateway pushed from FortiOS.

string

- none

dst-addr

Read-only: Destination IP addresses

string

- none

services

Read-only: Internet services.

options

- none
config members
Parameter Description

Type

Size

Default

config member

Interfaces within the virtual switch.

option

-

none

name

The LAN port ID.

string

-

none

type

Interface type.

option

-

port

Interface within the virtual switch.

option

-

vap

Virtual Access Point, which must NOT be configured as a WLAN bridge, will be added as a member of the switch-interface.

option

-

vids

VLAN ID list.

integer

1 to 4089

pvid

Port VLAN ID.

integer

1 to 4089

security-8021x-member-mode

Enable/disable 802.1x authentication on a port.

option

-

config system switch-interface

config system switch-interface

Description: View LAN extension settings synced from the FortiGate. You cannot configure these settings directly on the FortiBranchSASE; you must make them through the FortiGate LAN extension profile first.

config system switch-interface
  edit <name>
    set vlan-support [enable | disable]
    config member 
      edit <name1> 
        set type [ aggregate | physical | vap]
        set port
        set vids {1-4089}
        set pvid {1-4089} 
        set security-8021x-member-mode [enable | disable]
      next
    end
    set stp [enable | disable]
    set td-mode [disable | include]
    set wired-security-mode [802.1X]
    set wired-security-group <security group ID>
  next
end

Sample syntax:

config system switch-interface
  edit lan
    set vlan-support disable
    config member
      edit port4
        set type physical
        set port port4
        set vids
        set pvid 1
        set security-8021x-member-mode enable
      next
    end
    set stp disable
    set ts-mode disable
    set wired-security-mode 802.1X
    set wired-security-group test
  next
end
Parametrer Description Type Size Default

vlan-support

Enable/disable VLAN support.

option

-

stp Spanning Tree Protocol. option - disable
Option Description
enable Enable Spanning Tree Protocol.
disable Disable Spanning Tree Protocol.

ts-mode

Read-only: Split tunnel mode.

option

-

disable

Option Description
include Enable Split tunnel mode
disable Disable Split tunnel mode.

wired-security-mode

Turn on 802.1x authentication for this interface.

option

-

wired-security-group

Names of user groups that can authenticate with the 802.1X.

option

-

dst-mac

Read-only: MAC address of the remote gateway pushed from FortiOS.

string

- none

dst-addr

Read-only: Destination IP addresses

string

- none

services

Read-only: Internet services.

options

- none
config members
Parameter Description

Type

Size

Default

config member

Interfaces within the virtual switch.

option

-

none

name

The LAN port ID.

string

-

none

type

Interface type.

option

-

port

Interface within the virtual switch.

option

-

vap

Virtual Access Point, which must NOT be configured as a WLAN bridge, will be added as a member of the switch-interface.

option

-

vids

VLAN ID list.

integer

1 to 4089

pvid

Port VLAN ID.

integer

1 to 4089

security-8021x-member-mode

Enable/disable 802.1x authentication on a port.

option

-