Fortilink L3
Hello,
situation:
2x FG200F connected to a HP Comware switch cluster via LAG (2x2x10Gbit)
Bought 13x Fortiswitch 148F as access switches
Default VLAN on the trunk is the legacy network and won't be easily changed
Several VLANs on that trunk working as intended, fortigate is primary router for legacy network and several DMZs
Spanning VLANs via L2 Fortilink is not needed, just Centralized Management and eventually NAC configuration
Original plan was to create a management VLAN (3) and have the Fortiswitches managed from the Fortigate UI, mostly based on Fortilink over TCP – InfoSec Monkey.
On the FG200F Fortilink is configured to an unused interface (10.255.3.1).
Policy allowing VLAN3 to fortilink interface is active.
The interface facing the fortiswitch uplink (port49) has PVID 3.
The switch can ping the IP of the fortigate on VLAN3 (10.100.3.1), and also the fortilink interface through that network as a gateway. I can see the CAPWAP attempts on the fortigate interface capture on VLAN3, but the fortigate doesn't respond to that, only for the NTP.
The interface facing the fortiswitch has PVID 3
What am I missing? I am considering using Fortilink over VXLAN from the official documentation to circumvent this issue, but this seems like another extra layer of complexity which I would like to avoid, as adding extra cables to the core switches
Kind regards,
Michael
