Skip to main content
claydawg
Explorer
February 8, 2024
Question

Same VLAN on Multiiple Fortilink Interfaces

  • February 8, 2024
  • 9 replies
  • 7369 views

I have a scenario where there are two different Fortilink interfaces on a FortiGate. I need to extend a particular VLAN from the gate to both Fortilink-managed switches. Unfortunately this requires me to require a VLAN sub-interface on each Fortilink interface. One has an IP address configured and the other is just 0.0.0.0/0. I assumed, maybe incorrectly, that this would just do 802.1q and pass layer-2 between interfaces but I also know this is a firewall and that sort of behavior may not work. Can anyone confirm if this is supported? If not, is the only solution to re-architect this and reconfigure for only a single Fortilink?

9 replies

Stephen_G
Staff & Editor
Staff & Editor
February 11, 2024

Hello claydawg,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen_G - Fortinet Community Team
Stephen_G
Staff & Editor
Staff & Editor
February 13, 2024

Hello claydawg,

 

This document may help you with what you need: https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/454200/multiple-fortiswitches-managed-via-hardware-software-switch

 

Let me know if you need further help, or feel free to contact us.

 

Kind regards,

Stephen_G - Fortinet Community Team
claydawg
claydawgAuthor
Explorer
February 23, 2024

Thanks, Stephen. Unfortunately I don't see anything in that docs that answers my question. I'm really hoping there is a way to make this work. I just don't see the value in FortiLink. It seems like it just makes traditional networking more difficult and restrictive.

hbac
Staff
Staff
February 24, 2024

Hi @claydawg,  

 

I would suggest configuring only a single fortilink to manage both switches. 

 

Regards, 

claydawg
claydawgAuthor
Explorer
April 16, 2024

Thanks. This is a huge drawback of FortiLink. I understand the simplicity of it, but it really limits your ability to customize the network after the fact.

AEK
SuperUser
SuperUser
April 16, 2024

Hi @claydawg 

  • Are your FSW interconnected? Do they need to be interconnected?
  • Do your FSW support ICL or ISL?
  • Why do you need to the VLAN to both FSW?
  • Why you need to use 2 FortiLinks?

If you elaborate a bit more maybe we can help.

AEK
claydawg
claydawgAuthor
Explorer
April 17, 2024

Why do I need to extend the same VLAN to two different switches? I can't even believe I'm being asked that question. I don't mean to be rude but this is a common practice on any network. There's no need to justify the necessity.

freeman91
New Member
December 3, 2024

Hi, I have read entire topic and still I can not believe that If I have two fortilink on fortigate, I can not have the same vlan o two FL??
So, I we build new rack on different floor, I have to continue my current fortilink from the last switch to the new rack on next floor?

sw2090
SuperUser
SuperUser
December 3, 2024

It is common use that a vid is unique per interface. Its the same everywhere. If you need more lines you will need a switch. This can be a physical one next to your FGT or you could create a vswitch out of your fortilink ports on your FGT (which they already are by factory default AFAIR).Then just create a vlan interface on that switch and you can use your vlan on every fortilink port.

sjoshi
Staff
Staff
December 3, 2024

Creating VLAN sub-interfaces with the same VLAN ID on multiple FortiLink interfaces on a FortiGate is not supported. Each VLAN sub-interface must have a unique VLAN ID to avoid conflicts. To extend a particular VLAN to both FortiLink-managed switches, consider reconfiguring the network architecture to use a single FortiLink interface for the VLAN to ensure proper functionality and avoid potential issues with duplicate VLAN IDs on different interfaces.

Thanks, Salon
FrancoisBlanchon
Visitor III
December 18, 2024

Hi @claydawg,

I have the same question, but I cannot find any usefull answer unfortunately. So did you succeed to setup several Fortiswitch loops, each connected through its own fortilink with a same VLANID setup on each FLink (in order to have a same VLAN on several switch loops)? Actually I know that the VLANID tagging will not be the issue, but it is at the layer3 level that the question is. The layer 3 GW handled by FGT, will be only on one Flink only. Then my question is, should it work with policies between Flinks ? to make possible the communication between hosts from on switch loop 1 to VLAN GW, and the same from hosts on switch loop 2 ?
Insane for me to write this, hope I will never have to implement fortiswitches in large campus env.
thx for your feedback.

Javo
Visitor III
February 21, 2025

The FortiSwitches solution has some topology limitations that other vendors do not have. In your case, although it is not cost-effective, it is recommended to place a distribution switch between the FortiGate and the switches. This way you have more freedom and options to design regular topologies normally used in enterprise campuses.