My setup:
1x FG80E
1x FS108D
1x FS224D
3x FAP421E
I have a home network/Lab with the above mentioned products. One FortiAP and the FS224D was added today.
The FS108D is connected to the FG via Dedicated to FortiSwitch on port 12. This switch is the main switch, where all networks and APs are connected via VLANs.
Today I added the FS224D to port 11 and on that switch I added the third FortiAP. Then I authorized both devices. This is where the problems start:
[ul]My build is probably all wrong since I get the feeling that logic from working with other brands does not apply here. I've used the cookbooks to set it all up but unfortunately they don't cover my scenario so I've improvised some. I've already started from scratch several times when I reached the end of the rope. Feels like thats where I'm heading again with this many problems. Mind that it's all been working for months before I tried to add that new HW.
I have plowed through most of the documentation, searching for keywords but I'm not finding good answers. From my description above, what can you guys read out?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Check this,possibly help you.
http://makcotechgeek.com/fortigate-5-4-4-fortiswitch-3-3-5-fortiap-5-4-1/
Regards.
What are your versions and firmware for everything? Are they all versions that inter-operate?
Have you enabled auto-discovery-fortilink on the switch ports you're connecting to with:
config switch interface edit <port> set auto-discovery-fortilink enable end
Are you allowing admin access CAPWAP for the interfaces (vlan or otherwise) that your FortiAPs are connected to?
Have you rebooted the FortiSwitches an additional time, through GUI, SSH, or just pulling the plug? Various FortiSwitch versions in the past had some issues when initially connected that are resolved by an additional reboot.
The problem was that FortiOS does not support more than one(1) dedicated switchport and I tried to configure a topology requiring two ports.
My options were to either daisy-chain the switches or rebuild my network using a virtual/hardware switch and then add both switches to that. Since rebuilding is troublesome I chose the daisy-chain option.
It was all in the FortiOS guide, but it would not hurt to state in the cookbooks that only one interface is available for the dedicated switchport.
Agreed - would be helpful if the cookbook recipes mentioned the restriction.
As an aside, I think supporting multiple FortiLink interfaces without requiring the FortiGate's internal switch interface would be a very worthwhile feature. It would also make transitioning existing architectures to FortiSwitches much easier. Feel free to contact your Fortinet SE and request this as an NFR (new feature request)!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1669 | |
1082 | |
752 | |
446 | |
225 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.