Hello everyone,
I'm planning to set up two Fortigate 60F (with HA active/passive) and two Fortiwitchs 148F-POE.
Before the setup, I created a diagram and wanted to know if my topology was correct and i have questions.

- My configuration is correct ?
- Do I need to create a trunk between the two switches, or is it not necessary?
- Does FortiLink Split Interface need to be enabled? If so, on both FortiLink interfaces A and B of the main Fortigate ?
Thank you for your help.
Chris
Hi @Chris32 ,
For answers to your questions and to ensure seamless redundancy between your FortiGate HA pair and dual FortiSwitches, follow this design:
When a FortiGate fails, the FortiSwitches will continue to operate and maintain FortiLink with the secondary FortiGate (now active). MCLAG ensures that endpoints connected to the FortiSwitches maintain connectivity through whichever FortiGate is active.
Additionally, I’ve highlighted the necessary connections in a sample setup and shared them with you in the image below.
BR.
If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.
CCIE #68781
Hi Atakan Atak !
Thank you for your feedback.
If I'm not mistaken, it's not possible to use MCLAG with 148F-POE switches. Isn't that possible starting with the 200 series?
I'm new to Fortinet and wanted to do this configuration as simple as possible.
Thank you in advance for your feedback.
Chris
Hi @Chris32 ,
As you pointed out, it does appear that the 148F models might not be supported. To be honest, I wasn’t aware of this either. However, just to be sure, it would be helpful to confirm whether the configurations from the previous references have also been applied on the FortiSwitch CLI side.
You can also find the full feature matrix in the article linked below, which lists all supported features:
In that case, the topology you mentioned would be the most suitable approach and aligns with best practices. Regarding your questions:
Q1-Your configuration is correct.
Q2/3-In this scenario, the only condition that affects the need for a connection between the switches depends on how you configure the split-interface setting:
BR.
If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.
CCIE #68781
User | Count |
---|---|
2624 | |
1390 | |
804 | |
667 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.