Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tezro
New Contributor

Fortilink (switch - fortigate) over media converter not working ...

Hello,   The issue is: why Fortilink cannot be established over a media converter ? What are the limitations ...? Vendors of ""proper"" media-converters ??? I thought that media converter is only a dump converter: from electric signals to optical -so it does not introduce anything in the traffic -> ergo it completely transparent and FolrtiLink shoul (!) works   What about config like this Of course : -FG is configured for FortLink on the port that is connected to the media-converter -SFP are proper for the fiber : SFP SM for SM fiber type -Link on BOTH sides are UP and blinking... [F-Gate UTP] <--Cat 5e copper --> [ UTP  MediaConverter  SFP] <--Fiber --> [SFP  FortiSwitch]   any magic command from CLI (again...!) on Fgate or Fswitch ?????   UPDATE: the SAME Fortinet SFP module plugged from switch to Fluke Analyzer and connected via media-converter to normal  (non-fortilink) port in FGate  works from the first kick ...   WTH ?!?!?!?   THA   Tezro

10 REPLIES 10
bmduncan34
New Contributor III

Why can't you just do all fibre or all copper between the gate and the switch?

Tezro

I'd love to, really! but ....

I have a couple of installations where FG-80x is to big (mostly 50x 60x) ... and this is a lowest model with SFP additionally pre-configured as WAN.

I know, I can change this to different port but still

Fortilink over third party devices (switches, wifi-bridges) is not straight-forward solution

 

brycemd
Contributor II

So, the connection in general works as a normal interface, but it's not activating fortilink?

 

There's really only a handful of things needed for fortilink... Make sure DHCP server is on the interface, make sure NTP is listening, and make sure the port on the switch has the isl profile applied so it actually attempts to negotiate fortilink. The isl profile isn't always enabled on all ports on the switch, but I would expect it to be enabled on sfps by default.

 

There are typically 2 lldp profiles on the switch, one labeled default and one labeled default-auto-isl. Only the ports that have the default-auto-isl will have fortilink enabled.

pcarbonneau50

I just had the same problem. Two FortiGates 60F in HA connected to two FSW124E-FPOE for redundancy and this works.

Then when we connect a switch in another room through a fiber (tested) and through media converters, The port on the main room goes up but the switch never connects. If we move that switch to the main room and connect it using a network cable, then the switch comes up no problem. We move it back to the other room and connect it to the fiber again, nothing.. niet.. nada

 

We will try a different model of media converter as this setup has already been done in another building by another cabling company and everything worked. 

 

Edit: We tried the SFP module that come with the media converters into the FortiSwitches and it worked even if the FortiGate gives a message that the module is not from Fortinet. So the only thing that was removed is the media converter itself. 

 

To make sure we do not have a problem with Fortinet support in the future, we will buy SFP transceivers to connect them in the switches to do the uplink.

pyy
New Contributor III

 

Hi Tezro,

 

The most of the media converters cannot understand vlans (802.1q) and thats why you are having this behaviour.

Tezro

OK ... but ...

I always thought that that media-converters are always dumb L1 devices and they don't care about such complicated things like VLAN from another, far L2 world ...

They receive the electrical signals and change them to optical and vice versa -that's all ...

SBarr
New Contributor

After finding this topic while having the exact same issue, I saw the response by PYY and looked further into it.  After ordering converters that specifically supported VLAN traffic, it's working perfectly. I was using converters from 10Gtek and they were not working.  I switched to a converter by AD-net and it worked right away, just like using a regular ethernet cable.

BreakerBoy
New Contributor III

Which model of AD-net worked? I have AD-net as well, states that it works with vlans, but it does not work. Specifically, it's this model - https://www.amazon.com/Multimode-Gigabit-Fiber-Converter-Built/dp/B07DWXXTT9.

BB
BB
Faiza_Emam_Delhi
Contributor II

Hello

 

FortiLink is a proprietary protocol that is used by Fortinet to establish a secure link between FortiGate and FortiSwitch devices. It's designed to work over Ethernet cables or fiber optic cables, and it's not recommended to use media converters between the devices.

 

Media converters are designed to convert signals from one media type to another, such as from copper to fiber optic or vice versa. While media converters are transparent to the traffic passing through them, they can introduce latency, jitter, and other issues that can cause problems with FortiLink.

 

Additionally, Fortinet recommends using Fortinet-branded SFP modules in both FortiGate and FortiSwitch devices to ensure optimal performance and compatibility. Using third-party SFP modules can cause issues with FortiLink and other Fortinet features.

 

If you need to connect FortiGate and FortiSwitch devices over a long distance, it's recommended to use fiber optic cables and repeaters instead of media converters. Fortinet also offers a range of network switches that are designed to work seamlessly with FortiGate devices, such as the FortiSwitch series.

 

Regarding your updated information, it's possible that the FortiLink protocol is not properly configured on the FortiGate or FortiSwitch devices. You may need to verify the configuration settings on both devices and ensure that the FortiLink protocol is enabled and configured correctly.

 

I hope this helps! Let me know if you have any further questions.

Thanks & Regards,
Faizal Emam
Thanks & Regards,Faizal Emam
Labels
Top Kudoed Authors