I have used FortiSwitches in a couple locations, but always managed by a FG.
I will have a need at a location soon for some advanced configuration to support IP Video traffic on one of the VLANs, but features like IGMP Snooping and Querier don't seem to be exposed in the FG interface. Can you configure these settings through CLI while still being managed by the FG, or does FG management effectively wipe the configuration and load its own from the FG?
If you can do both, can you configure with CLI at any time while connected to the FG, or only before or after adding it to the FG as a managed switch?
TIA,
-David
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
With the 3.6.x switch OS you could make some changes in the CLI after the switch became managed that stayed between firmware updates. The one I used the most was setting switch ports to have discard-mode all-tagged. Note that you can now set discard-mode from the FortiGate with 6.0.x, and upgrading to the 6.0.x firmware wiped my discard-mode settings on 1 of our 6 switches (a 124E).
Note that IGMP Snooping is supposed to be supported on managed FortiSwitches above 1xxE models, though release notes still list some bugs.
ehenvironments wrote:Yes, if you configure the switch via the FS CLI, your custom config will get wipe after making changes on the FG....or does FG management effectively wipe the configuration and load its own from the FG?
The proper way to do this is in the FG CLI. Use the commands 'config switch-controller managed-switch', 'edit <FS serial number>' then 'config igmp-snooping'.
Excellent, thanks for the insight. We will give it a try.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.