Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
plsikk
New Contributor III

How to manage fortiswitch via fortilink over non fortiswitches

Hello again.

Another topic 

I have to replace some switches to Forti switches but will not be directly connected to FG . Already prepare some test environment for this configuration and I'm stuck on the "red"

connection is:

FG - FS1- HPE1- HPE2 - FS2

Already did all steps from this article - " FortiLink over a point-to-point layer-2 network" and I see the SF2 is discovered by FG but is permanently offline. How to troubleshoot this.

what I did on HPE , I set vlan 4094 as native on ports where FS2 is connected, set  other needed vlans as tagged, tagged all vlans between HPE1 and HPE1 , but I don't know which vlan I need to set on port on FS1 . Weird is that FS2 joined to FG but is still offline. On both HPE also disabled LLDP services. Any suggestions ?

 

 

Best regards
Best regards
4 REPLIES 4
sta
Staff
Staff

I believe fsw uses by default VLAN 1

config switch global

  set fortilink-p2p-native-vlan 1

end

 

What is the output of: execute switch-controller get-conn-status from the FGT ?

 

You could also try using L3

Technical Tip: FortiLink mode over a layer-3 netwo... - Fortinet Community

 

plsikk
New Contributor III

Hi

Already setup with half success . But in my case this was compilation of two articles. via L2 and L3

Between two forti switches I have HPE switch. 

Connection looks like FG connected toFS1,  FS1(port7) connected to HPE(port10), HPE(port9) connected to FS2.

So on FS1 I set this

config switch physical-port

edit port7

set fortilink-p2p enable

end

Config ports on HPE looks like below

 

interface 9
tagged vlan 1,199
untagged vlan 4094
exit
interface 10
tagged vlan 199,4094
untagged vlan 1
exit

on FS2 also set

config switch physical-port

edit port48

set fortilink-p2p enable

end

After this just disabled CDP and LLDP services on HPE and few min later FS2 joined to FG and is online. but status in FG is like below

S248EFTF21019899 v7.2.4 () Authorized/Down - 0.0.0.0 

 

Best regards
Best regards
DanielaLeia
New Contributor


@plsikk wrote:

Hello again.

Another topic 

I have to replace some switches to Forti switches but will not be directly connected to FG . Already prepare some test environment for this configuration and I'm stuck on the "red"

connection is:

FG - FS1- HPE1- HPE2 - FS2

Already did all steps from this article - " FortiLink over a point-to-point layer-2 network" and I see the SF2 is discovered by FG but is permanently offline. How to troubleshoot this.

what I did on HPE , I set vlan 4094 as native on ports where FS2 is connected, set  other needed vlans as tagged, tagged all vlans between HPE1 and HPE1 , but I don't know which vlan I need to set on port on FS1 . Weird is that FS2 joined to FG but is still offline. On both HPE also disabled LLDP services. Any suggestions ?

 

 


No, Fortigate fortiswitch management requires Fortilink. You can run Fortilink over L3 though, if that's what you're after.

It would make things much easier if you tried to explain what the end goal is, what you're trying to accomplish.

plsikk
New Contributor III

I need to connect and manage FS by FortiGate but devices are not connected directly . Between is HPE switch. But I need to manager this FS from FortiManger

in my second case, to the same Fortigate I need to connect 3 Fortri swiches (other building) which is connected via 60Ghz Mikrotik bridge (Wire Dish), and the same goal. Manage fs from Forti Manager

Best regards
Best regards
Top Kudoed Authors