- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Remove Fortiswitches from Fortigate management process
I'm new to the Fortinet switch world. We have a customer that is replacing their existing Fortigate 60F firewalls that also manage the switches and access points. We're replacing the APs, so those aren't an issue. I'm looking for guidance on the switches though. I think i have the process down for changing the management method and ChatGPT tells me the config will stay in place (for the most part). Is this the proper command to change the management and is ChatGPT correct about the config?
set switch-controller-mode standalone
I'm also having a hard time connecting CLI to the devices from the Fortigate management UI. From what I've read the admin credentials that I'm using to log into the Fortigate should work on the switches, but some refuse those creds and some give me a message that my password doesn't conform to the policy, must be changed, then it spits me out of the command and returns the same message if i try to connect again. I'd like to get into these devices before we plan the hardware change. Does anyone have any suggestions? The previous IT company is not forthcoming with information and just tells me everything is managed from the Fortigate, and to politely go pound sand.
This is my first post, If I'm breaking forum rules or protocol in some fashion forgive me. If you point out an error I won't repeat it. Thanks.
- Labels:
-
Authentication
-
FortiSwitch
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
To remove FortiSwitches from the FortiGate management process, you can deauthorize the devices by following these steps:
- On the root FortiGate, go to Security Fabric -> Fabric Connectors.
- In the topology tree, click on the FortiSwitch device you want to remove.
- Select the option to Deauthorize the device.
After deauthorizing the devices, their serial numbers will be saved in a trusted list.
You can view this list in the CLI using the command 'show system csf.' This action effectively removes the FortiSwitch from the Security Fabric managed by the FortiGate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you Anthony_E. Does this leave the existing configuration in place.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You may refer this as well: https://docs.fortinet.com/document/fortiswitch/7.6.1/fortilink-guide/173266/discovering-authorizing-...
and on the FSW CLI, you may disable auto-network.https://docs.fortinet.com/document/fortiswitch/7.6.1/fortilink-guide/657004/zero-touch-management
config switch auto-network
set status disable
end
Sachit Das
ETAC Engineer
Wifi-Switching – International Support
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This one is not actually working on my terminal too.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
facing the same issue repeadetly
