Access to Fortiswitch via Fortilink
Hello all I have recently inherited a network of Fortinet gear. It was mostly setup reasonably well, but there were a number of issues. It consists of 2 60F which are setup in HA. 3 FortiSwitch 248E-FPOE, and 6 Forti AP 221E. I have managed to work out most of what needed to be done. However one odd thing lingers.
I have all my FortiSwitch online and accessible through FortiLink, as well as Forti AP managed. The FortiLink address is 10.109.92.1, and my FortiSwitch are 10.109.92.2/3/4. From any Fortiswitch I can ping and access the other (for instance from 10.109.92.2 I can SSH to one of the other FortiSwitch at 10.109.2.3). However I cannot from any switch ping the FortiLink interface of 10.109.92.1, nor from the GUI can I access any Fortiswitch via CLI. My only option right now to access the Fortiswitch directly if I wanted to is to use a console cable.
One challenge I faced was that when I was given this setup the Fortiswitch would not connect via FortiLink. What I discovered was that NTP was not functional. The FortiSwitch had the FortiLink IP as NTP but since none of the switches can reach that IP NTP was not functional. I worked around it temporarily by writing a CLI Firewall policy between FortiLink and the Internet. I then used a NTP Server on the public internet and then each switch connected via FortiLink.
So something on my 60F is blocking this traffic. I can post any config necessary to assist with figuring this out. I am not sure I explained this properly.
