Description | This article describes why issues may be faced with setting capture on the FortiLink port connected to FortiGate. |
Scope | FortiSwitch (in FortiLink only). |
Solution |
This behavior is noticed on a FortiSwitch FortiLink trunk/port that is connected to FortiGate.
sh switch trunk config switch trunk edit "G200E4Q16XXXXX" set mode lacp-active next end
When attempting to configure the mirror directly on this FortiSwitch, any of these errors may appear:
Error1: entry not found in datasource =====
S248EFTF18XXXXXX # config switch mirror
===== config switch mirror edit f2 new entry 'f2' added set dst port30 end
Note that the FortiSwitch would have been configured with RSPAN that is pushed from the FortiGate upon enabling the traffic sniffer.
config switch mirror edit "flink.sniffer" set status active next end
config switch mirror
After deleting the config, it should be possible to configure the mirror for a FortiLink uplink directly on the FortiSwitch. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.