config system switch-interface
Description: View LAN extension settings synced from the FortiGate. You cannot configure these settings directly on the FortiBranchSASE; you must make them through the FortiGate LAN extension profile first.
config system switch-interface
edit <name>
set vlan-support [enable | disable]
config member
edit <name1>
set type [ aggregate | physical | vap]
set port
set vids {1-4089}
set pvid {1-4089}
set security-8021x-member-mode [enable | disable]
next
end
set stp [enable | disable]
set td-mode [disable | include]
set wired-security-mode [802.1X]
set wired-security-group <security group ID>
next
end
Sample syntax:
config system switch-interface
edit lan
set vlan-support disable
config member
edit port4
set type physical
set port port4
set vids
set pvid 1
set security-8021x-member-mode enable
next
end
set stp disable
set ts-mode disable
set wired-security-mode 802.1X
set wired-security-group test
next
end
| Parametrer | Description | Type | Size | Default | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
|
vlan-support |
Enable/disable VLAN support. |
option |
- |
|
||||||
| stp | Spanning Tree Protocol. | option | - | disable | ||||||
|
||||||||||
|
ts-mode |
Read-only: Split tunnel mode. |
option |
- |
disable |
||||||
|
|
|
|||||||||
|
wired-security-mode |
Turn on 802.1x authentication for this interface. |
option |
- |
|
||||||
|
wired-security-group |
Names of user groups that can authenticate with the 802.1X. |
option |
- |
|
||||||
|
dst-mac |
Read-only: MAC address of the remote gateway pushed from FortiOS. |
string |
- | none | ||||||
|
dst-addr |
Read-only: Destination IP addresses |
string |
- | none | ||||||
|
services |
Read-only: Internet services. |
options |
- | none | ||||||
config members
| Parameter | Description |
Type |
Size |
Default |
|
|---|---|---|---|---|---|
|
config member |
Interfaces within the virtual switch. |
option |
- |
none |
|
|
|
name |
The LAN port ID. |
string |
- |
none |
|
|
type |
Interface type. |
option |
- |
|
|
|
port |
Interface within the virtual switch. |
option |
- |
|
|
|
vap |
Virtual Access Point, which must NOT be configured as a WLAN bridge, will be added as a member of the switch-interface. |
option |
- |
|
|
|
vids |
VLAN ID list. |
integer |
1 to 4089 |
|
|
|
pvid |
Port VLAN ID. |
integer |
1 to 4089 |
|
|
|
security-8021x-member-mode |
Enable/disable 802.1x authentication on a port. |
option |
- |
|