Skip to main content
rcpdkc
Explorer II
February 24, 2024
Solved

Fortiswitch Multiport 3+

  • February 24, 2024
  • 13 replies
  • 3629 views

Hello, I have a 1101f series firewall. I want to connect 6 fortiswitches. When I connect the switches over fortilink by jumping from each other, there is no problem and all of them get ip and the connection status is actively monitored. However, when I need to connect with different 6 ports of the firewall (due to the wiring structure of the building), I enter 6 ports into fortilink. When I connect the switches, they get ip first, but the connections go immediately. DHCP does not work and they cannot get ip. What is the reason for this?

In addition, I created a fortilink port as a Hardware Switch. When I put the ports into it, all switches get ip but only 2 of them seem to be active. I can reach the others but they do not seem active. What could be the reason for this?

Best answer by rcpdkc

The document I gave in the link gives all the details required for the connection.

https://community.fortinet.com/t5/FortiSwitch/Technical-Tip-How-to-Single-FortiGate-unit-manages-multiple/ta-p/259359

 

After applying the given document, it did not appear active except for 2 devices. Later, when I entered the fortiswitch interface, I saw that the time was incorrect. I entered the gateway address of the switches as ntp server and the time was corrected. Devices went online.

13 replies

AEK
SuperUser
SuperUser
February 25, 2024

Hello @rcpdkc 

Which firmware versions in firewall and switches?

AEK
rcpdkc
rcpdkcAuthor
Explorer II
February 25, 2024

Fortios 7.0

AEK
SuperUser
SuperUser
February 25, 2024

What is the X in your FOS 7.0.X?

And what is the firmware version inside the FortiSwitches?

AEK
ebilcari
Staff
Staff
February 26, 2024

So the switches are not connected to each other and you want to terminate all their uplinks directly in FGT and configure them all to be in FortiLink mode?

If this what you are trying to achieve than this is not a common/recommended topology, you can refer to the topology section of the guide for more options, maybe consider some extra cabling.
NOTE: Using the hardware or software switch interface in FortiLink mode is not recommended in most cases. It can be used when the traffic on the ports is very light because all traffic across the switches moves through the FortiGate unit.

Emirjon
rcpdkc
rcpdkcAuthor
Explorer II
February 27, 2024

Actually, the topology I have given below is exactly what I want. However, it does not give any information about how to do it.

https://docs.fortinet.com/document/fortiswitch/7.4.2/fortilink-guide/801202/single-fortigate-unit-managing-multiple-fortiswitch-units-using-a-hardware-or-software-switch-interface

ebilcari
Staff
Staff
February 27, 2024

Than make sure you don't have any loop (switches should have only the uplink connected to FGT and the end hosts) and verify that STP is not disabling any of the ports. From the architecture of this model there should be no differences of the chosen ports when building the HW switch.

Emirjon
rcpdkc
rcpdkcAuthorAnswer
Explorer II
February 27, 2024

The document I gave in the link gives all the details required for the connection.

https://community.fortinet.com/t5/FortiSwitch/Technical-Tip-How-to-Single-FortiGate-unit-manages-multiple/ta-p/259359

 

After applying the given document, it did not appear active except for 2 devices. Later, when I entered the fortiswitch interface, I saw that the time was incorrect. I entered the gateway address of the switches as ntp server and the time was corrected. Devices went online.

AEK
SuperUser
SuperUser
February 27, 2024

Nice catch.. Thanks for sharing the info.

Indeed, missing NTP leads in so much and diverse issues.

AEK
rcpdkc
rcpdkcAuthor
Explorer II
February 28, 2024

In the Fortiswitch interface, the default gateway must be written in the NTP server section at the bottom.8.PNG

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!