Skip to main content
Sharique62
Explorer
August 8, 2026
Question

Creating a Layer 2 VLAN 700 Bridge on FortiGate 200F Between Two FortiSwitches

  • August 8, 2026
  • 5 replies
  • 90 views

I would like to understand whether the following design is possible and, if so, how it can be configured on a FortiGate 200F or 600F.

Current Topology:


FortiSwitch 124F ── FLINK_INET_1 ────┐
                                                               FortiGate 200F
FortiSwitch 548D ── fortilink ───────┘


FortiSwitch 124F-POE

VLAN 700 configured with IP address 11.11.11.1/30
Connected to FortiGate 200F via a FortiLink-enabled interface i.e FLINK_INET_1.

FortiGate 200F

Connected to both FortiSwitches using separate FortiLink-enabled interfaces.
Requirement is to configure VLAN 700 as a Layer 2 bridge only, without Layer 3 routing on the FortiGate.

FortiSwitch 548D-FPOE

VLAN 700 configured with IP address 11.11.11.2/30
Connected to FortiGate 200F via another FortiLink-enabled interface i.e fortilink.


Requirement

I need VLAN 700 traffic to pass transparently through the FortiGate 200F, effectively allowing the two FortiSwitches to communicate as if they were on the same Layer 2 VLAN.

Question

How can VLAN 700 be configured on the FortiGate 200F to operate as a Layer 2 bridge between the two FortiSwitches?

Is it possible when both switch connections are configured as independent FortiLink interfaces?
Would a software switch, hardware switch, VLAN trunking, or another bridging mechanism be required?
Are there any FortiLink design limitations that would prevent extending VLAN 700 between separately managed FortiSwitches through the FortiGate? 

5 replies

Stephen_G
Staff & Editor
Staff & Editor
August 11, 2026

Hi Sharique62,

Thank you for using our forums. We’ll look to get you an answer or help.

In the meantime, if anyone else has any advice: please feel free to contribute.

Stephen_G - Fortinet Community Team
GauravPandya
Explorer
August 11, 2026

Hi Sharique,

Extending a single VLAN in a pure Layer 2 bridge mode between two separate FortiLink-managed FortiSwitch units directly through FortiGate is not natively supported, because FortiLink treats VLANs as locally terminated interfaces on the FortiGate control plane rather than transparently bridging switch ports across independent FortiLink paths.

Connecting switches to separate FortiLink interfaces on the FortiGate creates distinct logical segments. You cannot use a software switch or hardware switch inside the FortiGate to tie two separate FortiLink VLAN sub-interfaces together into a transparent Layer 2 bridge.

 

If you need the two switches to communicate transparently on VLAN 700 at Layer 2 without routing on the firewall, consider this option:

MCLAG (Multi-Chassis Link Aggregation): Connect the FortiSwitches using an MCLAG topology back to the FortiGate. This pools the links into a single logical FortiLink aggregate interface, natively sharing the same Layer 2 VLANs across all member switches.

Sharique62
Explorer
August 13, 2026

Hi Gaurav,
 

Thanks for sharing. I tested this using a Virtual Wire Pair (VWP).

I created the required VLANs on the existing FortiLink aggregates and grouped those logical VLAN interfaces into a hardware-accelerated VWP. I then bound the corresponding VLAN sub-interfaces to their respective VWPs.

 

Sharique62
Explorer
August 13, 2026

I have updated the topology to include redundancy at each layer:

  • FortiSwitch 124F-A and 124F-B connected via an ISL on Port5
  • FortiGate 200F-A and 200F-B configured in HA using Port9 and Port10  
  • FortiSwitch 548D-A and 548D-B configured as an MCLAG pair using Port9 and Port10

The current issue is that the ISL connection between the two 124F switches is not establishing and remains down.

GauravPandya
Explorer
August 17, 2026

Hi Sharique,

Verify physical link status
get switch physical-port port5

Verify ISL configuration
show switch interface port5

Check LLDP discovery
diagnose switch-controller switch-info managed-switch <switch_serial>

Verify whether each 124F can see the neighboring 124F on Port5.
 

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!