Hi all,
I hope you're well.
I am migrating a site with existing Cisco switches to FortiSwitch but will not be using the default FortiLink interface since the VLAN's are already created under the existing aggregate interface. Templates have been configured and will be pushed out via FortiManager however, in order to add the switches into FortiManager I must issue set fortilink enable as a FortiLink interface must exist on the FortiGate.
If I make the interface a FortiLink interface by using this command, does it remain as a standard trunk so that the Cisco switches and assigned VLAN's remain servicing clients meaning I can do this in hours or does this interface only work when a FortiSwitch is detected making this service affecting in hours if connected to Cisco switches?
My thoughts are that this would not affect anything, but I have not tested issuing this command with anything other than a FortiSwitch attached so wanted to confirm.
Thanks!
Enabling FortiLink on an existing aggregate interface may alter its behavior, as FortiGate will expect to manage FortiSwitches dynamically. While Cisco switches should still pass traffic, VLAN handling might be affected, so it's safer to configure FortiLink on a separate, unused port instead of modifying the existing trunk.
You still have two options: (1) Configure the FortiSwitch as a standalone switch, though this may not be feasible for your case if you need centralized management via FortiManager, or (2) Temporarily enable FortiLink on an unused interface to satisfy FortiManager’s requirement, then proceed with the migration while keeping your current network intact.
Hi FranceSimao,
Thanks for your response.
This was my original thinking however, I did manage to test this and although it didn't affect VLAN handling and the Cisco switches could still pass traffic without issues it is still safer to do as you mentioned if you want to push configuration beforehand.
In my case, I had all the switch templates, custom commands etc configured in FMG and within my designated outage window just issued set fortilink enable on the required interface which then allowed me to add the required switches into FMG and assign the pre-configured templates which worked well.
If I ever need to do this beforehand, I will definitely go with what you suggested and deploy the configuration by assigning the switches to an unused FortiLink interface, then proceeding with the migration which would allow the current network to stay intact.
Many thanks,
Dan.
User | Count |
---|---|
2530 | |
1350 | |
795 | |
639 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.