Skip to main content
Epsilon
New Member
February 10, 2025
Question

Remove Fortiswitches from Fortigate management process

  • February 10, 2025
  • 5 replies
  • 4586 views

I'm new to the Fortinet switch world.  We have a customer that is replacing their existing Fortigate 60F firewalls that also manage the switches and access points.  We're replacing the APs, so those aren't an issue.  I'm looking for guidance on the switches though. I think i have the process down for changing the management method and ChatGPT tells me the config will stay in place (for the most part). Is this the proper command to change the management and is ChatGPT correct about the config?

set switch-controller-mode standalone

 

I'm also having a hard time connecting CLI to the devices from the Fortigate management UI.  From what I've read the admin credentials that I'm using to log into the Fortigate should work on the switches, but some refuse those creds and some give me a message that my password doesn't conform to the policy, must be changed, then it spits me out of the command and returns the same message if i try to connect again.  I'd like to get into these devices before we plan the hardware change.  Does anyone have any suggestions?  The previous IT company is not forthcoming with information and just tells me everything is managed from the Fortigate, and to politely go pound sand.

 

This is my first post, If I'm breaking forum rules or protocol in some fashion forgive me.  If you point out an error I won't repeat  it.  Thanks.

5 replies

Anthony_E
Staff
Staff
February 13, 2025

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks

Best Regards
Anthony_E
Staff
Staff
February 13, 2025

Hi,

 

To remove FortiSwitches from the FortiGate management process, you can deauthorize the devices by following these steps:

  1. On the root FortiGate, go to Security Fabric -> Fabric Connectors.
  2. In the topology tree, click on the FortiSwitch device you want to remove.
  3. Select the option to Deauthorize the device.

After deauthorizing the devices, their serial numbers will be saved in a trusted list.

You can view this list in the CLI using the command 'show system csf.' This action effectively removes the FortiSwitch from the Security Fabric managed by the FortiGate.

Best Regards
Epsilon
EpsilonAuthor
New Member
February 18, 2025

Thank you Anthony_E.  Does this leave the existing configuration in place.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.