Skip to main content
tanr
New Member
November 20, 2017
Question

Initial questions on FortiGate control of multiple FortiSwitches

  • November 20, 2017
  • 7 replies
  • 20836 views

Hi All,

 

I'll be doing some quick proof on concept work next week with a 5.4.6 FortiGate controlling a couple 3.6.3 108D-POE FortiSwitches. This is mostly to see if larger FortiSwithces might work for a different location.

 

I've run through the documentation, but have some questions before I get started, most of them basically boiling down to: Is there any way to manage FortiSwitches from the FortiGate but do it through distinct (not hardware/software switch) interfaces?

[ol]
  • Even with multiple FortiSwitches, all examples show a SINGLE FortiLink interface (which could be a hardware or software within the FortiGate spanning multiple physical ports) connecting to the switches (which may have ISL between them).  See http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-managing-fortiswitch-330-54/Stacking.htm examples.  This is required?  I can't have two SEPARATE FortiLink interfaces to further separate the switches?  Even if I set fortilink-stacking disable?
  • Related to #1, the only way shown to create VLANs for the managed FortiSwithches shows the VLAN interfaces being created on the (single) FortiLink interface as in http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-managing-fortiswitch-330-54/VLANconfig.htm.  Thus all VLANs get trunked through the FortiLink.  No way to have VLANs on other FortiGate interfaces if I want to manage those VLANs on the FortiSwitch?  Why not?
  • All the examples I've found show the FortiGate only connecting to FortiSwitch(es) through a FortiLink connection.  Can the switch also have connections to other FortiGate interfaces?  How about to non-FortiLink VLAN interfaces on the FortiGate?[/ol]

    As you can probably tell, most of this is trying to figure out a way to manage a FortiSwitch from the FortiGate but still keep its VLANs and other interfaces as separated as possible.  This is to make it harder to accidentally break security with a single error, like the incorrect vlan being set on a switch interface.  One use case is for a bunch of IP security cameras on a single switch.  Really don't want to plug that back into our lan!

    • 7 replies

      tanr
      tanrAuthor
      New Member
      November 22, 2017

      Still haven't found a way to have separate physical interfaces on the FortiGate for separate VLANs unless I use VDOMs or unless I don't have the FortiGate manage the FortiSwitch.

       

      Anybody else?

      Prab
      New Member
      December 14, 2017

      Hi Tanr,

       

      Regarding the Question1:

      A fortiGate can only have one fortiLink at the moment. This fortiLink can be a single interface or a logical interface (software switch or 802.3ad aggregate interface etc.) In case you plan to use a logical link, make sure you understand the limitations of the logical links.

       

      Regarding Question2:

      This is true and this is by design. You can still create VLANs on FortiGate too, but yes it looks bit messy.

       

      Regarding Question3:

      Long story short please do not do this. It might work (I tested it in my Lab and it worked), but it is not a supported topology, so at the end of the day FortiNet Support has right to tell you to run off, in case you open a support ticket for any topology that is officially not supported by the FortiGate/FortiLink/FortiSwitch. for Example: The following topology worked in my lab fine, but as per FortiNet support this is not supported officially. ;)

      Hope this was helpful.

      Thanks & regards,

      Prab

      tanr
      tanrAuthor
      New Member
      December 14, 2017

      Hi Prab,

       

      Thanks for the info.  The picture helps explain your "non-supported" config nicely.  What you said matches most of what I've worked out so far. 

       

      One additional question I haven't found an answer to yet (I have the question open with TAC) is if there is a good way to have CLI access to the FortiSwitches, not just have them managed by the FortiGate.  The switch-controller custom-commands are not sufficient for our needs.

       

      I have seen descriptions of how to set this up with a managed FortiSwitch if it has a dedicated management port. See https://docs.fortinet.com/uploaded/files/2742/manageFSWfromFGT54.pdf "Configuring FortiSwitch Management Port" for details. However I can't seem to get this to work for my 108D-POEs, which have no management port. 

       

      Any suggestions on how to get/keep CLI access to the FortiSwitches after they are managed by the FortiGate?

      Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
      Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!