Created on 06-15-2022 03:46 AM Edited on 06-15-2022 06:28 AM By Anonymous
Description |
This article describes how to manage FortiSwitch Fortilink port config cannot be modified from FortiGate.
From FortiGate, when changing the FortiSwitch Fortilink port status, the config does not gets applied to the FortiSwitch. |
Scope |
FortiGate and FortiSwitch 6.4.x, 7.x. FortiSwitch managed by FortiGate. |
Solution |
This article describes the behaviour when attempting to push config from the FortiGate to the FortiSwitch port which is part of the FortiLink trunk.
Refer to the example below:
FortiGate 6.4.9 is managing FortiSwitch 6.4.7. FortiSwitch port7 is part of ISL FortiLink trunk.
# FGT# execute switch-controller get-conn-status S108EF v6.4.7 (478) Authorized/Up - 169.254.1.6 Wed Jun 15 14:01:56 2022 access2
FortiSwitch:
# access2 # sh switch trunk
Now, from the FortiGate, change the port status to down:
FG200E (root) # config switch-controller managed-switch FG200E (managed-switch) # edit S108EF FG200E (S108EF) # config ports FG200E (ports) # edit port7 FG200E (port7) # set status down FG200E (port7) # end FG200E (S108EF) # end
Run the below debug on FortiSwitch and the below logs is visible:-
access2 # diag debug cli 8 access2 # diag debug console timestamp enable access2 # diagnose debug enable
Port status remains UP and does not get changed. This is expected behaviour, do not change FortiSwitch's FortiLink port config from FortiGate. NOTE: There are some exceptions like pushing the LLDP profile to the FSW Fortilink ports from the FGT. https://docs.fortinet.com/document/fortiswitch/7.0.4/devices-managed-by-fortios/801208/transitioning...
# access2 # sh full-configuration switch physical-port port7 . . set status up
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.