Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Deepfriedrolos
New Contributor II

Fortilink Issues though non Fortinet Switch

Hi,

 

Have a bunch of Fortinet switches and they all are connected fine via Fortilink with 1 exception. The setup looks like this for this exception,

 

Fortigate --- Fortiswitch1 --- Netgear Switch ---- Fortiswitch2

 

I can no manage Fortiswitch2 though the fortigate.

 

I have looked online for the last few days and cant seem to find anyone that has cracked this issue so im coming directly to the forums.

 

Could someone explain what the configuration on the Netgear switch should look like please.

 

 

7 REPLIES 7
fricci_FTNT
Staff
Staff

Hi @Deepfriedrolos ,

 

Have you tried to configure the Netgear ports where the FortiSwitches are connected with mgmt VLAN as native (by default it should be 4094 unless you changed it):

Fortiswitch1 --- [native 4094]-Netgear Switch-[native 4094] ---- Fortiswitch2

Try to packet capture the traffic on those two Netgear ports and analyse it with Wireshark to investigate where the problem can be.

Best regards,
Federico

---
If you have found a useful article or a solution, please like and accept it to make it easily accessible to others.
Deepfriedrolos

Yes, I have tried that.

On the netgear i have created vlan 4094 and set the PVID of both ports that connect the Fortiswitches to 4094. I have also tried tagging and untagging 4094 from these ports with no success.

 

 

fricci_FTNT

Hi @Deepfriedrolos ,

Thank you for letting me know.
I would suggest you to run a packet capture on the Netgear port and on the FortiSwitch related ports, then analyse them with Wireshark and compare.

The article below might help with FortiSwitch packet capture (please read the article to properly packet capture):

https://community.fortinet.com/t5/FortiSwitch/Technical-Tip-How-to-collect-sniffer-captures-in-each-...

 

You could run something similar to the below from CLI, then convert it with in Wireshark readable format:
diagnose sniffer packet <port-number> "" 6 100 l 

 

To convert:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-import-diagnose-sniffer-packet-data...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-import-diagnose-sniffer-packet-data...


On the FortiGate do you see the authorise request from FortiSwitch2? If not, the following might help:

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Fix-FortiSwitch-showing-with-the-Off...


The following link might help as well:
https://docs.fortinet.com/document/fortiswitch/7.4.4/fortilink-guide/801183/fortilink-over-a-point-t...

Best regards,

---
If you have found a useful article or a solution, please like and accept it to make it easily accessible to others.
Deepfriedrolos

Are there any detailed documents on how the Fortilink protocol works? Doesn't seem to be alot of information out there on that. I don't really see the point in wiresharking anything as i don't know what I'm looking for.

 

Does Forinet have a TAC team like Cisco i can raise this with.

fricci_FTNT

Please find some FortiLink/FortiSwitchOS documentation below:
https://docs.fortinet.com/document/fortiswitch/7.4.6/fortilink-guide/173260/configuring-fortilink
https://docs.fortinet.com/document/fortiswitch/7.4.6/fortilink-guide/173258/optional-fortilink-confi...

The troubleshooting article below also can provide some hint:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Fix-FortiSwitch-showing-with-the-Off...


If you have a valid FortiCare contract, you can raise a ticket with the FortiSwitch TAC using FortiSwitch2 serial number from the support portal:
https://support.fortinet.com/

 

Best regards,

---
If you have found a useful article or a solution, please like and accept it to make it easily accessible to others.
Deepfriedrolos

So after doing some testing i have found the following..

 

If i take the trunk link from the netgear and put it into a cisco switch i have and set the native vlan on the cisco side to 4094, everything works fine.

 

My question now is, how do you set the native vlan as 4094 on Fortiswitch1? It doesn't seem to allow that via the GUI at least.

 

filiaks1

VLANs and VLAN tagging | FortiSwitch 6.4.6 | Fortinet Document Library the command " set native-vlan" in there what do you mean not allowed ? Also why not select another vlan for native between the two systems.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors