Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ryan_Kang
New Contributor

Feature Request – ACL Enhancements and Interface Range Configuration for Managed FortiSwitch

Hello,

 

I'm reaching out as I couldn’t find the proper place to submit feature requests on the Fortinet website (such as support or partner portals). Therefore, I'm sharing this feedback here in the community forum in hopes it reaches the appropriate team.

 

One of my customers operates a network with approximately 100 FortiSwitches, all integrated via FortiLink with FortiGate.

 

Managing ACLs on FortiSwitches in this environment has been extremely frustrating.

 

Here’s the issue:
I want to apply ACLs that allow or deny traffic based only on destination service ports, while keeping source and destination IPs as 'any'. This is a very common requirement in real-world environments. However, this configuration is not possible when the FortiSwitches are managed by FortiGate via FortiLink.

 

The managed FortiSwitch ACL configuration lacks the ability to define service ports. There is also no option to disable FortiGate control over ACLs, which means that even if I manually configure ACLs directly on each FortiSwitch, those configurations are erased after a certain period—presumably because FortiGate has no corresponding configuration and overwrites them.

 

This is understandable, but still unacceptable in operational environments.

 

Please consider adding the ability to configure ACLs based on service ports directly from FortiGate for managed FortiSwitches.

 

Furthermore, FortiSwitches, unlike other vendors, do not support interface range configuration in CLI, which makes batch operations incredibly time-consuming and error-prone.

 

If you’ve ever tried to configure ACLs on FortiSwitch via FortiGate, you’d know how painful the process is:
You must create the ACL, group it, and then go into each switch to apply it to individual ports one by one. This is an inefficient and unrealistic approach, especially in large-scale deployments.

 

Please improve these features that are most commonly used in real-world operations.
Not being able to configure ACLs based on service ports in managed FortiSwitch mode is deeply disappointing.

 

It would be ideal if there were a setting that allows engineers to choose whether FortiGate should manage ACLs on FortiSwitch or not.

 

In many cases, managing ACLs directly on the FortiSwitch is more practical and preferred, and I believe many other network engineers would agree.

 

Thank you for your consideration.

I am the center of the world. BY, SmileStory :)
I am the center of the world. BY, SmileStory :)
1 Solution
Stephen_G

Hi Ryan,

 

Yes, contact a local sales engineer in your country via email if you can. I'm afraid I can't find the online sections you mean either.

 

I hope that helps!

Stephen - Fortinet Community Team

View solution in original post

3 REPLIES 3
Stephen_G
Moderator
Moderator

Hi Ryan_Kang,

 

Thanks for reaching out!

 

For new feature requests, contact your Fortinet Account Manager. They will make contact with the right team to evaluate the feature. From there, we'll evaluate the feature and its potential benefit.

 

I hope that helps!

Stephen - Fortinet Community Team
Ryan_Kang

Hello Stephen_G,

 

I would like to ask how I can get in touch with a Fortinet Account Manager.

Should I contact a Fortinet engineer or sales representative in my country via email?

 

I recall that there used to be a section on the support website for product or feature inquiries, but I can no longer find it.

 

Do I need to reach out to Fortinet directly via phone or by emailing the appropriate contact person?

 

Thank you in advance for your guidance.

 

Best regards,
Ryan Kang

I am the center of the world. BY, SmileStory :)
I am the center of the world. BY, SmileStory :)
Stephen_G

Hi Ryan,

 

Yes, contact a local sales engineer in your country via email if you can. I'm afraid I can't find the online sections you mean either.

 

I hope that helps!

Stephen - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors