Skip to main content
bshimkus
New Member
September 18, 2017
Question

Add Fortiswitch ports to a Fortigate software switch?

  • September 18, 2017
  • 3 replies
  • 7806 views

Hey everybody,

 

Is it possible to add the interfaces from a FortiSwitch FS-108D-POE (3.6.2) to a software switch on a FortiGate-60E (5.6.2)?

 

I'm assuming no, as I've doing some pretty extensive Googling and came up empty.

 

Or, does the 60E just not support it?

 

Thanks in advance for the help!

 

bks

 

(Posting in FortiGate forum as well...)

    3 replies

    Prab
    New Member
    December 18, 2017

    bshimkus wrote:

    Hey everybody,

     

    Is it possible to add the interfaces from a FortiSwitch FS-108D-POE (3.6.2) to a software switch on a FortiGate-60E (5.6.2)?

     

    I'm assuming no, as I've doing some pretty extensive Googling and came up empty.

     

    Or, does the 60E just not support it?

     

    Thanks in advance for the help!

     

    bks

     

    (Posting in FortiGate forum as well...)

    Hi Bshimkus,

     

    I am not sure if that is possible possible, to increase the port density of a FortiGate by using ports from the fortiSwitch.

     

    Why would you like to do it?

    Also be aware that software switch might create loops, in case you make wrong cable connections from the FortiGate to the same fortiSwitch.

     

    Thanks & regards,

    Prab

    bshimkus
    bshimkusAuthor
    New Member
    December 18, 2017

    The use case was to basically extend my FG60E switch ports to the FS-108D-POE so that I wouldn't have to mess with VLANs, multicast policy, etc.

     

    I had separate broadcast domains for wireless, Fortigate, and Fortiswitch clients, but due to my lack of experience with Fortinet products, it proved to be more complicated than it was worth.  Devices that relied on Bonjour (or other multicast requirements) simply didn't work unless I put all devices in the same broadcast domain (hence, the software switch combining wireless and wired interfaces all together).  I tried numerous multicast policies allowing traffic between them all, but it just didn't cooperate.

     

    I ended up setting the FortiSwitch as unmanaged (in the aspect of not using FortiLink).

     

    I agree that creating loops could be a possibility in the software switch scenario.  Given that the environment is so small, it's a concession I've made.

     

    I'd really like to re-engineer the whole setup, however I doubt the users will give me enough grace to figure it all out. :)

     

    bks

    Prab
    New Member
    December 19, 2017

    bshimkus wrote:

    The use case was to basically extend my FG60E switch ports to the FS-108D-POE so that I wouldn't have to mess with VLANs, multicast policy, etc.

     

    I had separate broadcast domains for wireless, Fortigate, and Fortiswitch clients, but due to my lack of experience with Fortinet products, it proved to be more complicated than it was worth.  Devices that relied on Bonjour (or other multicast requirements) simply didn't work unless I put all devices in the same broadcast domain (hence, the software switch combining wireless and wired interfaces all together).  I tried numerous multicast policies allowing traffic between them all, but it just didn't cooperate.

     

    I ended up setting the FortiSwitch as unmanaged (in the aspect of not using FortiLink).

     

    I agree that creating loops could be a possibility in the software switch scenario.  Given that the environment is so small, it's a concession I've made.

     

    I'd really like to re-engineer the whole setup, however I doubt the users will give me enough grace to figure it all out. :)

     

    bks

    I am too not a multicast fan, I once had a similar problem. I was not able to pass the multicast traffic between two different VLANs. However in this case the gateway was a sonicwall, although I had a IPv4 policy which allowed everything between two VLANs. :D

    I am not sure if you have to play with the frame size etc.

     

    I would open a support case here, to really figure out the cause.

    Good luck.

     

    Thanks & regards,

    Prab :)

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!