Transparent Mode VLAN Forwarding: Required Configurations
An administrator is configuring a VLAN interface on a FortiGate. The physical interface is port2 and the VLAN ID is 100. Which of the following correctly creates the VLAN interface?
⚠ Common exam trap
A common mix-up: candidates confuse the FortiGate CLI with Cisco IOS, where `interface port2.100` automatically implies a VLAN subinterface without needing an explicit `set type vlan` or `set vlanid` command, leading them to choose Option C or D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
config system interface edit port2.100 set vlanid 100 set type vlan next end
It uses the correct CLI syntax to create a VLAN subinterface on a FortiGate. The command `config system interface` enters the interface configuration context, `edit port2.100` creates or edits the subinterface named with the physical interface and VLAN ID, `set vlanid 100` assigns the VLAN tag, and `set type vlan` explicitly defines the interface type as VLAN. This matches the required configuration for 802.1Q VLAN tagging on FortiGate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
config system interface edit port2.100 set vlanid 100 set type vlan next end
Why this is correct
The correct CLI creates a VLAN subinterface by editing port2.100 under config system interface. The name uses the dot notation to associate the subinterface with physical port2; set vlanid 100 tags traffic with 802.1Q VLAN 100, while set type vlan marks the interface as a VLAN interface. This sequence fully defines the logical interface and is the only valid way to add a VLAN on a FortiGate.
- ✗
config system interface edit port2 set vlanid 100 next end
Why it's wrong here
This command enters the physical interface port2, not a VLAN subinterface, and attempts to execute 'set vlanid', which is an invalid parameter for a physical interface. On FortiOS, a VLAN ID is not a property of a physical port; it belongs only to a subinterface created with a dot-number name. Trying to set it on port2 results in a configuration error, so the VLAN never gets created.
- ✗
config system interface edit port2.100 set type vlan next end
Why it's wrong here
Here a subinterface port2.100 is edited and set as a VLAN, but the mandatory 'set vlanid 100' is omitted. Without the vlanid parameter, FortiGate has no tag to associate with the interface, so it cannot know which 802.1Q VLAN this logical port represents. As a result, the interface remains incomplete and the VLAN configuration fails to be applied.
- ✗
config system vlan edit port2.100 set vlanid 100 next end
Why it's wrong here
This command references a nonexistent 'config system vlan' configuration node. In FortiOS, all interfaces, including VLAN subinterfaces, are defined exclusively under 'config system interface'; there is no separate VLAN object. Even if the edit name and set commands are correct, placing them under the wrong path means the device rejects the command, so the VLAN interface is never created.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.