Hi All,
We have an ISP providing us layer 2 to several sites via a QinQ tunnel. I have seen having an ISP in between devices is not supported for a L2 FortiLink; however, several people have had success doing so.
The issue is currently that FortiLink establishes for a small period of time if freshly factory reset and mgmt vlan settings are changed to 4094. This will establish the link, then FortiGate sends configs. After a while the CAPWAP tunnel goes down and the switch never comes back online.
FortiNet support mentioned this could be an STP issue, though they weren't willing to further investigate as the ISP devices may be playing a role. I confirmed via packet capture the only STP packets being received are that of the upstream FortiSwitch.
Any insight to how these setups are working, or configuration that assist this would be helpful! We are very close with the ISP, and they are always willing to work with us, so any insight to what they might be able to do is also appreciated.
With set fortilink-p2p enable on the physical interface we can get the switch to come up temporarily.
We get the following output after the switch has gone offline:
The behavior seems odd. Again, any insight would be appreciated!
I have exact the Same issue!
Did you find any solution?
Switch comes online, i do authorize, it gets its name and goes offline... spf+ port is back to factory defaults. No FortiLink Port...
I would appreciate any help!
Hi there
i was successfull with the following configuration over mpls -->
FortiLink over a point-to-point layer-2 network
Starting in FortiSwitchOS 6.4.0, you can run FortiLink mode over a point-to-point layer-2 network. You can form an inter-switch link (ISL) between two FortiSwitch units over a layer-2 device or non-FortiSwitch device (such as a wireless bridge). The LLDP destination MAC address is changed to the broadcast MAC address to bypass middle layer-2 devices. For example:
To create this topology, you configure ports on both ends of the link as described in the following procedure and, optionally, configure the tag protocol identifier (TPID) between the two FortiSwitch units.
NOTE:
config switch physical-port
edit <port_name>
set fortilink-p2p enable
end
config switch global
set fortilink-p2p-tpid <0x0001-0xfffe>
end
on switch2 do the following change also
config switch auto-network
set mgmt-vlan 4094
set status enable
end
I tried p2p too. But didn't come online in the first step (doesn't show up after factoryreset and management vlan set to 4094).
User | Count |
---|---|
2640 | |
1400 | |
810 | |
685 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.