Hello everyone!
I'm new with Fortiswitch and I have 6 to integrate now in my network. I have two FGT100E (HA cluster) and I want to manage all the fortiswitch from the Fortigates. I found some configuration step into Fortigate web site but there's some things that I can understans or isn't very clear for me.
Here're my questions:
1. If I configure STP, do I have to configure my fortigates as Root-Bridge?
2. There is some feature or parameter that I have to configure for STP or default configuration is gonna be ok?
3. I'm going to configure LAG between the fortiswitchs and between them and the Fortigates, can I configure the management VLAN inside these LAGs or I have to configure dedicated ports in the fortigate only for management the fortiswitch (Fortilinks)
Thanks in advance!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
laupin wrote:Hello everyone!
I'm new with Fortiswitch and I have 6 to integrate now in my network. I have two FGT100E (HA cluster) and I want to manage all the fortiswitch from the Fortigates. I found some configuration step into Fortigate web site but there's some things that I can understans or isn't very clear for me.
Here're my questions:
1. If I configure STP, do I have to configure my fortigates as Root-Bridge?
2. There is some feature or parameter that I have to configure for STP or default configuration is gonna be ok?
3. I'm going to configure LAG between the fortiswitchs and between them and the Fortigates, can I configure the management VLAN inside these LAGs or I have to configure dedicated ports in the fortigate only for management the fortiswitch (Fortilinks)
Thanks in advance!
Hi Laupin,
Please find my comments below to your questions:
3. I'm going to configure LAG between the fortiswitchs and between them and the Fortigates, can I configure the management VLAN inside these LAGs or I have to configure dedicated ports in the fortigate only for management the fortiswitch (Fortilinks)
Just a heads up, in case the fortiswitches are being managed by a FortiGate, then it is a bad idea to configure them directly, it might cause inconsistent switch configurations running on the fortiSwitches & the fortiGate. By default the VLAN ID 1 is used for managing the fortiSwitches via the fortiLink. As far as I know, this cannot be changed!
1. If I configure STP, do I have to configure my fortigates as Root-Bridge?
2. There is some feature or parameter that I have to configure for STP or default configuration is gonna be ok?
By default STP will do its job, but yes in case you want to make sure that the STP selects a particular device as a Root, then try configuring it manually. I never did it.
Hope it was helpful.
Thanks & regards,
Prab :)
Thanks a lot. After a lot of troubles with my fortiswitch, I think I'm starting to understand them. You had right, it is a really bad idea to do any change directly into the fortiswitch when they are managed by the Fortigate. Another thing, Fortilinks are very sensible, you have to be sure of what you're configuring because in large environments it could be a nightmare. NTP, LLDP, STP, DHCP Snooping and IGMP snooping are the importants elements to consider in your configuration. I have my network in production now and I'm still having problems with the stability.
Thanks a lot again :)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1632 | |
1063 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.