Hi All,
I'll be doing some quick proof on concept work next week with a 5.4.6 FortiGate controlling a couple 3.6.3 108D-POE FortiSwitches. This is mostly to see if larger FortiSwithces might work for a different location.
I've run through the documentation, but have some questions before I get started, most of them basically boiling down to: Is there any way to manage FortiSwitches from the FortiGate but do it through distinct (not hardware/software switch) interfaces?
[ol]
Even with multiple FortiSwitches, all examples show a SINGLE FortiLink interface (which could be a hardware or software within the FortiGate spanning multiple physical ports) connecting to the switches (which may have ISL between them). See http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-managing-fortiswitch-330-54/Stacking.htm examples. This is required? I can't have two SEPARATE FortiLink interfaces to further separate the switches? Even if I set fortilink-stacking disable?Related to #1, the only way shown to create VLANs for the managed FortiSwithches shows the VLAN interfaces being created on the (single) FortiLink interface as in http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-managing-fortiswitch-330-54/VLANconfig.htm. Thus all VLANs get trunked through the FortiLink. No way to have VLANs on other FortiGate interfaces if I want to manage those VLANs on the FortiSwitch? Why not?All the examples I've found show the FortiGate only connecting to FortiSwitch(es) through a FortiLink connection. Can the switch also have connections to other FortiGate interfaces? How about to non-FortiLink VLAN interfaces on the FortiGate?[/ol]As you can probably tell, most of this is trying to figure out a way to manage a FortiSwitch from the FortiGate but still keep its VLANs and other interfaces as separated as possible. This is to make it harder to accidentally break security with a single error, like the incorrect vlan being set on a switch interface. One use case is for a bunch of IP security cameras on a single switch. Really don't want to plug that back into our lan!