What is the recommended setup for establishing a FortiLink connection between two FortiSwitches and two Fortigates in a high availability (HA -600E) setup ?
ISP 1 connects to Fortiswitch 1 and ISP 2 connects to Fortiswitch 2, both Fortiswitches are standalone switches. (No MCLAG between switches)
FGT Port 1 connects to Fortiswitch 1 and FGT Port 2 connects to Fortiswitch 2.
Created vlan interfaces for each ISPs(ISP 1 - Vlan 10 & ISP 2 - Vlan 20)
How do I add Fortilink between Fortiswitch and Fortigate ?
I think here is what you need.
The example on the document is for standalone FG but I think should be applicable to FG A-P HA as well.
@AEK, Both FGTs(600E) have aggregate bandwidth of 1G, Fortinet don't recommend Fortlink on hardware switch according to the above link(except can be used as alternative for high availability to use with entry level FGT models)
Hi @Dev82,
You can add port1 and port2 to an aggregate interface and enable fortilink on that interface. "fortilink-split-interface" should be enabled. FortiSwitches should be connected to each other for ISL.
config system interface
edit <>
set fortilink enable
end
You can also use a hardware switch: https://docs.fortinet.com/document/fortiswitch/7.0.8/devices-managed-by-fortios/801187/ha-mode-forti...
Regards,
@hbac Fortiswitches have not connected directly, both ports from switches need to enabled(unable to enable fortilink-split-interface) since FGT use both ISP links as the SDWAN member interfaces.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.