Skip to main content
thund31
New Member
October 19, 2020
Solved

200D connect to two switches

  • October 19, 2020
  • 1 reply
  • 4026 views

got a fortigate 200D old firewall in my company's lab environment.

i'm constructing a network topology with 200D and two switches(other brand), and these two SW are providing redundancy for end devices/servers. the topology is shown in attached figure.

 

well... i'm a newbie on networking and not familiar with fortinet's product at all, so my questions are stupid and hope you don't mind:

According to my topology, do i need to set STP on 200D to prevent network loop?

i want to make the interfaces(which connected to switches) on 200D isolate the switches' broadcast and also be the gateway for redundancy.

(i will also utilize L3 routing on switches for VLANs but these VLANs need to reach firewall for internet connection...)

therefore if one interface(on 200D) or switch dies, the other one could still provide network traffic for end devices.

 

is there any special settings from fortinet that i need to be aware of on 200D for my network topology??

 

thanks for answering my dumb questions.

    Best answer by Toshi_Esumi

    Since it's lab environment, you should test it with wireshark to figure out what would happen. It's a very good practice understanding L2 behavior on the FGT.

    As in the handbook, a FGT itself doesn't participate in STP. You can only enable forwarding STP frames.

    https://docs.fortinet.com/document/fortigate/6.0.0/handbook/857435/stp-forwarding

    When you configured a hard-switch including those two ports to two swiches, non-tagged and all VLANs on it are passed from one side to the other. You need to consider it as a single wire for another connection between two switches. So the switches are the ones to detect the L2 loop to block one side.

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    October 19, 2020

    Since it's lab environment, you should test it with wireshark to figure out what would happen. It's a very good practice understanding L2 behavior on the FGT.

    As in the handbook, a FGT itself doesn't participate in STP. You can only enable forwarding STP frames.

    https://docs.fortinet.com/document/fortigate/6.0.0/handbook/857435/stp-forwarding

    When you configured a hard-switch including those two ports to two swiches, non-tagged and all VLANs on it are passed from one side to the other. You need to consider it as a single wire for another connection between two switches. So the switches are the ones to detect the L2 loop to block one side.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!