Hello, The issue is: why Fortilink cannot be established over a media converter ? What are the limitations ...? Vendors of ""proper"" media-converters ??? I thought that media converter is only a dump converter: from electric signals to optical -so it does not introduce anything in the traffic -> ergo it completely transparent and FolrtiLink shoul (!) works What about config like this Of course : -FG is configured for FortLink on the port that is connected to the media-converter -SFP are proper for the fiber : SFP SM for SM fiber type -Link on BOTH sides are UP and blinking... [F-Gate UTP] <--Cat 5e copper --> [ UTP MediaConverter SFP] <--Fiber --> [SFP FortiSwitch] any magic command from CLI (again...!) on Fgate or Fswitch ????? UPDATE: the SAME Fortinet SFP module plugged from switch to Fluke Analyzer and connected via media-converter to normal (non-fortilink) port in FGate works from the first kick ... WTH ?!?!?!? THA Tezro
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Why can't you just do all fibre or all copper between the gate and the switch?
I'd love to, really! but ....
I have a couple of installations where FG-80x is to big (mostly 50x 60x) ... and this is a lowest model with SFP additionally pre-configured as WAN.
I know, I can change this to different port but still
Fortilink over third party devices (switches, wifi-bridges) is not straight-forward solution
So, the connection in general works as a normal interface, but it's not activating fortilink?
There's really only a handful of things needed for fortilink... Make sure DHCP server is on the interface, make sure NTP is listening, and make sure the port on the switch has the isl profile applied so it actually attempts to negotiate fortilink. The isl profile isn't always enabled on all ports on the switch, but I would expect it to be enabled on sfps by default.
There are typically 2 lldp profiles on the switch, one labeled default and one labeled default-auto-isl. Only the ports that have the default-auto-isl will have fortilink enabled.
I just had the same problem. Two FortiGates 60F in HA connected to two FSW124E-FPOE for redundancy and this works.
Then when we connect a switch in another room through a fiber (tested) and through media converters, The port on the main room goes up but the switch never connects. If we move that switch to the main room and connect it using a network cable, then the switch comes up no problem. We move it back to the other room and connect it to the fiber again, nothing.. niet.. nada
We will try a different model of media converter as this setup has already been done in another building by another cabling company and everything worked.
Edit: We tried the SFP module that come with the media converters into the FortiSwitches and it worked even if the FortiGate gives a message that the module is not from Fortinet. So the only thing that was removed is the media converter itself.
To make sure we do not have a problem with Fortinet support in the future, we will buy SFP transceivers to connect them in the switches to do the uplink.
Hi Tezro,
The most of the media converters cannot understand vlans (802.1q) and thats why you are having this behaviour.
OK ... but ...
I always thought that that media-converters are always dumb L1 devices and they don't care about such complicated things like VLAN from another, far L2 world ...
They receive the electrical signals and change them to optical and vice versa -that's all ...
After finding this topic while having the exact same issue, I saw the response by PYY and looked further into it. After ordering converters that specifically supported VLAN traffic, it's working perfectly. I was using converters from 10Gtek and they were not working. I switched to a converter by AD-net and it worked right away, just like using a regular ethernet cable.
Which model of AD-net worked? I have AD-net as well, states that it works with vlans, but it does not work. Specifically, it's this model - https://www.amazon.com/Multimode-Gigabit-Fiber-Converter-Built/dp/B07DWXXTT9.
Hello
FortiLink is a proprietary protocol that is used by Fortinet to establish a secure link between FortiGate and FortiSwitch devices. It's designed to work over Ethernet cables or fiber optic cables, and it's not recommended to use media converters between the devices.
Media converters are designed to convert signals from one media type to another, such as from copper to fiber optic or vice versa. While media converters are transparent to the traffic passing through them, they can introduce latency, jitter, and other issues that can cause problems with FortiLink.
Additionally, Fortinet recommends using Fortinet-branded SFP modules in both FortiGate and FortiSwitch devices to ensure optimal performance and compatibility. Using third-party SFP modules can cause issues with FortiLink and other Fortinet features.
If you need to connect FortiGate and FortiSwitch devices over a long distance, it's recommended to use fiber optic cables and repeaters instead of media converters. Fortinet also offers a range of network switches that are designed to work seamlessly with FortiGate devices, such as the FortiSwitch series.
Regarding your updated information, it's possible that the FortiLink protocol is not properly configured on the FortiGate or FortiSwitch devices. You may need to verify the configuration settings on both devices and ensure that the FortiLink protocol is enabled and configured correctly.
I hope this helps! Let me know if you have any further questions.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1720 | |
1094 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.