FortiSwitch
FortiSwitch: secure, simple and scalable Ethernet solutions
riteshpv
Staff
Staff
Article Id 269044
Description This article describes why only 8 FortiSwitches can be managed by a FortiGate and how to work around this limitation.
Scope FortiSwitch v6.4.x and above.
Solution

The topology connection is as follows:

 

                                                     topology-KB.jpg

 

Note:

Here, the 'Fortiswitch1' is a 100 series FortiSwitch (like FortiSwitch-108F, FortiSwitch-124E. Verify the datasheet of the FortiSwitch model => Check 'Total Link Aggregation Groups').

  • With this scenario, only eight FortiSwitches are present on a FortiGate. If trying to bring the 9th FortiSwitch, it does not come up.
  • The problem only arises if, as shown above, 'Fortiswitch1' is linked between FortiGate and another FortiSwitch.


Reason:

  • This relates to the maximum number of 'Total Link Aggregation Groups' a FortiSwitch can support. The lower-end FortiSwitches have a limit of 8 (Total Link Aggregation Groups), hence this limitation is breached in this example. But other FortiSwitches have 16, or no limitation (up to the number of ports), so check this limit before starting the design.
  • Upon the FortiSwitch's joining to form FortiLink, FortiLink trunk creation happens automatically.
  • In this scenario, the 'Fortiswitch1' will form a trunk to each FortiSwitch and also towards FortiGate. So one trunk (From Fortiswitch1) towards FortiGate and 7 FortiLinks trunks ('Fortiswitch2-Fortiswitch8') towards other FortiSwitches.
  • The 9th FortiSwitch ('Fortiswitch9') cannot form a trunk on 'Fortiswitch1' and thus will not come up on FortiGate.


Notes:

  1. Before connecting any downlink FortiSwitch to 'Fortiswitch1', if a manual trunk is established on 'Fortiswitch1', the number of FortiLink trunks that can be formed will be reduced. This limitation is specific to these models, allowing only 8 trunks to be formed, leading to a decrease in the number of FortiSwitches coming online.
  2. Depends on which trunk formed first. The first 8 trunks that were created will be considered regardless it was an automatic FortiLink trunk or a manually created trunk.

 

Solution:

  • It is better to use the higher-end model FortiSwitch to support more trunks. Refer to the FortiSwitch datasheet under 'Total Link Aggregation Groups'.
  • If it is not possible to have a higher model, then change the design of the connection to avoid a connection via a single FortiSwitch.