Hello all,
I have a problem where my two 448E switches are displayed as “online” under Managed Forti Switches. I can also access the port configuration and change it. So I guess the NTP is not the issue. NTP is also activated for the fortilink interface and set as Local.
However, in the topology, the connections are displayed as disconnected “dashed lines.” The MCLAG configuration is also not displayed correctly. Also with dash lines. But when I hover the mouse over the ports, MCLAG is shown as active.
When I go to “Diagnostics and Tools” for the respective switch, the ports are not displayed here. “CLI Access” also does not work. "Option is disabled because of the following reason(s)
FortiSwitch must have a valid assigned IP in order to connect to the CLI."
Also Faceplate will not show.
I have also checked whether “lldp-reception and lldp-transmission” is enabled in the fortilink interface. This is the case; it is enabled.
FGT01 # execute switch-controller get-conn-status
Managed-devices in current vdom root:
SWITCH-ID VERSION STATUS FLAG ADDRESS JOIN-TIME SERIAL
S448XXXXXXXXX v7.6.2 (1085) Authorized/Up 2 10.255.1.2 Mon Aug 4 16:28:23 2025 S448XXXXXXXXX
S448XXXXXXXXX v7.6.2 (1085) Authorized/Up 2 10.255.1.3 Mon Aug 4 16:29:06 2025 S448XXXXXXXXX
FGT01 # execute switch-controller diagnose-connection S448XXXXXXXXX
Fortilink interface ... OK
fortilink enabled
DHCP server ... OK
fortilink enabled
NTP server ... OK
fortilink enabled
NTP server sync ... OK
Timeout!
HA mode ... disabled
Fortilink
Status ... SWITCH_AUTHORIZED_READY
Last keepalive ... 0 seconds ago
CAPWAP
Remote Address: 10.255.1.2
Status ... CONNECTED
Last keepalive ... 7 seconds ago
PING 10.255.1.2 (10.255.1.2): 56 data bytes
64 bytes from 10.255.1.2: icmp_seq=0 ttl=64 time=0.4 ms
64 bytes from 10.255.1.2: icmp_seq=1 ttl=64 time=0.4 ms
64 bytes from 10.255.1.2: icmp_seq=2 ttl=64 time=0.6 ms
64 bytes from 10.255.1.2: icmp_seq=3 ttl=64 time=0.4 ms
64 bytes from 10.255.1.2: icmp_seq=4 ttl=64 time=0.4 ms
--- 10.255.1.2 ping statistics ---
5 packets transmitted, 5 packets received, 0% packet loss
round-trip min/avg/max = 0.4/0.4/0.6 ms
traceroute to 10.255.1.2 (10.255.1.2), 32 hops max, 3 probe packets per hop, 84 byte packets
1 10.255.1.2 0.362 ms 0.438 ms 0.293 ms
FGT01 (fortilink) # show
config system interface
edit "fortilink"
set vdom "root"
set fortilink enable
set ip 10.255.1.1 255.255.255.0
set allowaccess ping fabric
set type aggregate
set member "port1" "port2"
set device-identification enable
set lldp-reception enable
set lldp-transmission enable
set snmp-index 12
set auto-auth-extension-device enable
set fortilink-split-interface disable
set switch-controller-nac "fortilink"
set switch-controller-dynamic "fortilink"
next
end
FGT FW: v7.6.3 build3510 (Feature)
Switch FW: S448EP-v7.6.2-build1085,250526 (GA)
Thanks in advance.
Hello fabs,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello again fabs,
I found this solution. Can you tell me if it helps, please?
Based on the information provided, it seems that the FortiSwitches are recognized and authorized by the FortiGate, but there are issues with the topology display and CLI access. Here are some steps to troubleshoot and resolve the issue:
If these steps do not resolve the issue, consider reaching out to Fortinet support for further assistance.
User | Count |
---|---|
2593 | |
1382 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.