NSE4 · Question #31
A FortiGate is operating in NAT/Route mode and configured with two virtual LAN (VLAN) sub- interfaces added to the same physical interface. Which one of the following statements is correct regarding…
The correct answer is B. The two VLAN sub-interfaces must have different VLAN IDs. When configuring multiple VLAN sub-interfaces on a single physical interface in NAT/Route mode, each sub-interface must be assigned a unique VLAN ID.
Question
A FortiGate is operating in NAT/Route mode and configured with two virtual LAN (VLAN) sub- interfaces added to the same physical interface. Which one of the following statements is correct regarding the VLAN IDs in this scenario?
Options
- AThe two VLAN sub-interfaces can have the same VLAN ID only if they have IP addresses in
- BThe two VLAN sub-interfaces must have different VLAN IDs.
- CThe two VLAN sub-interfaces can have the same VLAN ID only if they belong to different
- DThe two VLAN sub-interfaces can have the same VLAN ID if they are connected to different L2
How the community answered
(39 responses)- B92% (36)
- C5% (2)
- D3% (1)
Why each option
When configuring multiple VLAN sub-interfaces on a single physical interface in NAT/Route mode, each sub-interface must be assigned a unique VLAN ID.
VLAN IDs are used for Layer 2 segmentation, not directly tied to IP address uniqueness across sub-interfaces on the same physical port for the same VLAN ID; two sub-interfaces on the same physical port cannot share the same VLAN ID regardless of their IP addresses.
In NAT/Route mode, each VLAN sub-interface represents a distinct logical interface operating over the same physical link, and each must be uniquely identified by its VLAN ID to correctly segment and route traffic. FortiGate uses the VLAN ID to demultiplex incoming tagged traffic to the correct sub-interface.
Two sub-interfaces on the same physical port cannot share the same VLAN ID, as the VLAN ID uniquely identifies the logical interface segment on that physical port.
While different L2 switches might terminate VLANs, on a single FortiGate physical interface, each VLAN sub-interface must have a unique VLAN ID to correctly demultiplex incoming traffic.
Concept tested: FortiGate VLAN sub-interface configuration
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469273/creating-vlan-subinterfaces
Topics
Community Discussion
No community discussion yet for this question.