I'm trying to set up a network environment where a FortiGate centrally manages a FortiSwitch. In the existing environment, all endpoint devices are assigned to different VLANs (such as 101, 201, 301, etc.), and all endpoint device IP gateways are configured on the core switch.
After successfully creating the FortiLink over a Layer 3 network to manage the FortiSwitch—following the reference link and documentation—I am able to manage and assign VLANs to the FortiSwitch from the FortiGate. However, I found that user traffic and DHCP assignment are also failing on the FortiSwitch. It seems the FortiSwitch cannot receive or forward any Layer 2 or Layer 3 traffic to the core switch.
Please advise if there is any misconfiguration or if you have any suggestions. Thank you very much!
Current Network Environment/HLD:
Internal Firewall (FortiGate) <-> Layer3 Core Switch (Cisco, H3C, Juniper, etc) <-> Access Switch (FortiSwitch) <-> User/Endpoint Devices
Refer by below reference document and link:
Hello MartinWong,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Thanks,
Not sure how your network structure is, it seems to hit the limitation of "FortiLink mode over a layer-3 network": No layer-2 data path component, such as VLANs, can span across layer 3 between the FortiGate unit and the FortiSwitch unit.
User | Count |
---|---|
2599 | |
1382 | |
803 | |
663 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.