Skip to main content
ghofer
New Member
March 26, 2023
Solved

Quick question about FortiAPs and FortiSwitches

  • March 26, 2023
  • 2 replies
  • 1567 views

Hello all, I come from a cisco background. Previously before picking up fortiswitches, we had to setup trunk ports to the fortiaps to pass the vlans for the SSIDs. On fortiswitches, do you setup the trunks within Fortigate as well for the fortiaps ?

 

Also, between fortiswitches I noticed LACP auto trunking took place. Is that the proper way to do it is just let fortilink pick up the switches and handle trunking or should I configure trunking static/fortinet trunking between switches.

 

Also, should a trunk be configured between the fortiswitches and fortilink port on the fortigate ?

 

Thank you in advance

Best answer by Toshi_Esumi

I'm also relatively new to any FSWs. But based on what I've learned with an FGT as a controller connected to the first FSW over fortilink then another FSW over ISL between two FSWs, I can tell you shouldn't try configuring those FSWs directly, which might conflict/confuse the controller FGT.
What I can tell with this arrngement is:
- All VLANs you configure on the FSWs (via the FGT's controller in GUI or CLI (under config switch-controller)) need to come to the FGT's fortilink port, which is automatic.
- "auto-ISL" (configured by default) automatically connects between FSWs and passes all VLANs configured under the switch-controller regardless it's actaully used or not.

- In the FSW world, these are not called as "trunk" while the term "trunk" is used to refer to LAG/LACP ports.
- Hidden VLAN ID 4094 is used inside of each FSW for the management interface, called "internal", and this VLAN is set as the native VLAN on the fortilink as well as the ISL interface port.

 

Again, once a FSW is authorized at the controler FGT, don't try configuring each FSW directly. Use direct CLI only for troubleshooting purposes.

 

Toshi

2 replies

Toshi_Esumi
SuperUser
SuperUser
March 27, 2023

I'm also relatively new to any FSWs. But based on what I've learned with an FGT as a controller connected to the first FSW over fortilink then another FSW over ISL between two FSWs, I can tell you shouldn't try configuring those FSWs directly, which might conflict/confuse the controller FGT.
What I can tell with this arrngement is:
- All VLANs you configure on the FSWs (via the FGT's controller in GUI or CLI (under config switch-controller)) need to come to the FGT's fortilink port, which is automatic.
- "auto-ISL" (configured by default) automatically connects between FSWs and passes all VLANs configured under the switch-controller regardless it's actaully used or not.

- In the FSW world, these are not called as "trunk" while the term "trunk" is used to refer to LAG/LACP ports.
- Hidden VLAN ID 4094 is used inside of each FSW for the management interface, called "internal", and this VLAN is set as the native VLAN on the fortilink as well as the ISL interface port.

 

Again, once a FSW is authorized at the controler FGT, don't try configuring each FSW directly. Use direct CLI only for troubleshooting purposes.

 

Toshi

ghofer
ghoferAuthor
New Member
March 27, 2023

That cleared up a lot for me. Thank you. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!