Hello,
(FortiOS 5.6)
the Hardware-Switch on FortiGate 61/81E seems to be limited to the numbered ports (internal1 to internal7), the Ports labeled WAN1, WAN2 and DMZ can only be used in a Software-Switch.
I am not concerned about performance (the few % are probably within the sizing we did) difference, i am however concerned about the following Feature of Hardware-Switch in HA configuration:
The the ports of a Hardware-Switch on the standby unit in a HA Active-Standby configuration function like a Layer-2 switch.
We use this in one of our sites with a Pair of FortiGate 140D to provide L2 redundancy without a local switch (by abusing the Standby unit as a secondary local switch). This requires the HW switch(es) of both FortiGates to be interconnected by cable, but it works fine.
We planned on using something similar on the 61/81E as well: by grouping WAN1 and WAN2 port into a hardware switch we wanted to be able to connect two uplink cables redundantly to both Fortigate units in a HA cluster without an additional L2-switch.
However this platform only supports Hardware-Switching on Ports Internal1-Internal7, the other ports can only be used in a Software-switch.
I really dont want to use Ports labeled "Internal" as the WAN uplinks and the WAN/DMZ ports for internal connection (although that is perfectly possible, I am just concerned that people will complain due to the labels).
My Question: Does the Software-Switch also work on a Standby-Unit in a Active-Passive HA cluster? Or is that feature only active on the Active Firewall?
Well, that's the hardware design of any "two-digit" models. On the other hand, that's the only difference between WAN/DMZ ports and LAN/Internal ports. I wouldn't mind at all using Internal1-2 as uplink connection.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1751 | |
1114 | |
766 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.