Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

Managing FortiSwitches through 3rd party L3 switches

Hello

I have 2 FG in A-P HA, connected to 2 3rd party L3 switches, connected to 2 3rd party L2 switches, as shown in the below diagram.

  • The FG ports are access ports (no VLAN tag) since they are connected to L3 switches
  • The FG reaches the VLANs defined on L2 switches via routes defined on the L3 switches
  • The FG ports do not have FortiLink enabled

s.png

I want to replace the 3rd party L2 switches with FortiSwitches.

When replacing them, what is the best way to manage the new FortiSwitches with FortiGate with minimum change to our existing architecture.

AEK
AEK
7 REPLIES 7
sahmed_FTNT
Staff
Staff

Hello, kindly see the below link for deployment options:
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/89ed3d92-8935-11ec-9fd1-fa163e...

Security all we want
AEK

Thanks for sharing.

Unfortunately I don't find there any suitable for my case.

AEK
AEK
DPadula
Staff
Staff
AEK

Hi @DPadula 

Thanks a lot for sharing. It is indeed very useful info.

However in my case there are two FortiSwitches and FG has two independent ports connected to the 3rd party L3 switches, while FortiLink must be on one sigle port logical or physical. What you think are the best options available for such case?

AEK
AEK
DPadula

Hi AEK
Are 3rd party L3 switches capable of work as single unit? Like Cisco stackwise or Juniper Virtual Chassis.

If you change the design to have both L3 switch working as a single unit might be a way, here are some options: https://docs.fortinet.com/document/fortiswitch/7.0.8/devices-managed-by-fortios/780635/switch-redund...
In case not, you might need to contact our SE team so they can help you out with the design. 

AEK

Thanks @DPadula for your advice.

In fact I did a mistake, I tested FortiLink interface on my FOS 6.2, on which only one interface (of any type) is supported. Then I found that there was improvement since then, so on 7.x it supports FortiLinks on multiple interface sets. This should help me find a solution.

I'll continue to dig and will share any findings.

AEK
AEK
DPadula

Hi @AEK 
Avoid 6.2.x once it is out of support.
6.4.x will be out of support in Sep/2024. So I suggest you to avoid new deployment with this firmware. Focus on 7.0, 7.2 and 7.4 from now. 

Labels
Top Kudoed Authors