I have a scenario where there are two different Fortilink interfaces on a FortiGate. I need to extend a particular VLAN from the gate to both Fortilink-managed switches. Unfortunately this requires me to require a VLAN sub-interface on each Fortilink interface. One has an IP address configured and the other is just 0.0.0.0/0. I assumed, maybe incorrectly, that this would just do 802.1q and pass layer-2 between interfaces but I also know this is a firewall and that sort of behavior may not work. Can anyone confirm if this is supported? If not, is the only solution to re-architect this and reconfigure for only a single Fortilink?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello claydawg,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello claydawg,
This document may help you with what you need: https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/454200/multiple-fortiswitches-managed-v...
Let me know if you need further help, or feel free to contact us.
Kind regards,
Thanks, Stephen. Unfortunately I don't see anything in that docs that answers my question. I'm really hoping there is a way to make this work. I just don't see the value in FortiLink. It seems like it just makes traditional networking more difficult and restrictive.
Thanks. This is a huge drawback of FortiLink. I understand the simplicity of it, but it really limits your ability to customize the network after the fact.
Hi @claydawg
If you elaborate a bit more maybe we can help.
Why do I need to extend the same VLAN to two different switches? I can't even believe I'm being asked that question. I don't mean to be rude but this is a common practice on any network. There's no need to justify the necessity.
Depending on your design requirements this is what you may need.
By setting FortiLink over HW/SW switch should allow you via one FortiLink to have the same VLAN(s) propagated to both FSW and the same gateway visible from the managed switches.
Hi, I have read entire topic and still I can not believe that If I have two fortilink on fortigate, I can not have the same vlan o two FL??
So, I we build new rack on different floor, I have to continue my current fortilink from the last switch to the new rack on next floor?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.