Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fabs
Contributor

WiFi & Switch Controller - Managed Switches shows disconnected

 

Hello all,

 

I have a problem where my two 448E switches are displayed as “online” under Managed Forti Switches. I can also access the port configuration and change it. So I guess the NTP is not the issue. NTP is also activated for the fortilink interface and set as Local.
However, in the topology, the connections are displayed as disconnected “dashed lines.” The MCLAG configuration is also not displayed correctly. Also with dash lines. But when I hover the mouse over the ports, MCLAG is shown as active.
When I go to “Diagnostics and Tools” for the respective switch, the ports are not displayed here.  “CLI Access” also does not work. "Option is disabled because of the following reason(s)
FortiSwitch must have a valid assigned IP in order to connect to the CLI."
Also Faceplate will not show.

I have also checked whether “lldp-reception and lldp-transmission” is enabled in the fortilink interface. This is the case; it is enabled.


FGT01 # execute switch-controller get-conn-status
Managed-devices in current vdom root:
SWITCH-ID VERSION STATUS FLAG ADDRESS JOIN-TIME SERIAL
S448XXXXXXXXX v7.6.2 (1085) Authorized/Up 2 10.255.1.2 Mon Aug 4 16:28:23 2025 S448XXXXXXXXX
S448XXXXXXXXX v7.6.2 (1085) Authorized/Up 2 10.255.1.3 Mon Aug 4 16:29:06 2025 S448XXXXXXXXX

 

FGT01 # execute switch-controller diagnose-connection S448XXXXXXXXX


Fortilink interface ... OK
fortilink enabled

DHCP server ... OK
fortilink enabled

NTP server ... OK
fortilink enabled
NTP server sync ... OK
Timeout!

HA mode ... disabled


Fortilink
Status ... SWITCH_AUTHORIZED_READY
Last keepalive ... 0 seconds ago


CAPWAP
Remote Address: 10.255.1.2
Status ... CONNECTED
Last keepalive ... 7 seconds ago


PING 10.255.1.2 (10.255.1.2): 56 data bytes
64 bytes from 10.255.1.2: icmp_seq=0 ttl=64 time=0.4 ms
64 bytes from 10.255.1.2: icmp_seq=1 ttl=64 time=0.4 ms
64 bytes from 10.255.1.2: icmp_seq=2 ttl=64 time=0.6 ms
64 bytes from 10.255.1.2: icmp_seq=3 ttl=64 time=0.4 ms
64 bytes from 10.255.1.2: icmp_seq=4 ttl=64 time=0.4 ms

--- 10.255.1.2 ping statistics ---
5 packets transmitted, 5 packets received, 0% packet loss
round-trip min/avg/max = 0.4/0.4/0.6 ms


traceroute to 10.255.1.2 (10.255.1.2), 32 hops max, 3 probe packets per hop, 84 byte packets
1 10.255.1.2 0.362 ms 0.438 ms 0.293 ms

 

 

 

FGT01 (fortilink) # show
config system interface
edit "fortilink"
set vdom "root"
set fortilink enable
set ip 10.255.1.1 255.255.255.0
set allowaccess ping fabric
set type aggregate
set member "port1" "port2"
set device-identification enable
set lldp-reception enable
set lldp-transmission enable
set snmp-index 12
set auto-auth-extension-device enable
set fortilink-split-interface disable
set switch-controller-nac "fortilink"
set switch-controller-dynamic "fortilink"
next
end

 

 

FGT FW: v7.6.3 build3510 (Feature)
Switch FW: S448EP-v7.6.2-build1085,250526 (GA)

Thanks in advance.

2 REPLIES 2
Jean-Philippe_P
Moderator
Moderator

Hello fabs, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Regards,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello again fabs,

 

I found this solution. Can you tell me if it helps, please?

 

Based on the information provided, it seems that the FortiSwitches are recognized and authorized by the FortiGate, but there are issues with the topology display and CLI access. Here are some steps to troubleshoot and resolve the issue:

 

  1. Verify IP Assignment: Ensure that the FortiSwitches have valid IP addresses assigned. The error message indicates that the CLI access is disabled due to the lack of a valid IP. Check the DHCP server settings on the FortiLink interface to ensure IPs are being assigned correctly.

  2. Check MCLAG Configuration: Since MCLAG is not displayed correctly, verify the MCLAG configuration on both the FortiGate and FortiSwitches. Ensure that the MCLAG settings are consistent and correctly configured.

  3. Review LLDP Settings: Although LLDP reception and transmission are enabled, double-check the LLDP settings on both the FortiGate and FortiSwitches to ensure they are configured correctly.

  4. Check Firmware Compatibility: Ensure that the firmware versions on the FortiGate and FortiSwitches are compatible. Sometimes, mismatched firmware versions can cause display and functionality issues.

  5. Examine Network Connectivity: Since the ping and traceroute tests are successful, network connectivity seems fine. However, double-check the physical connections and ensure that all cables and ports are functioning correctly.

  6. Review FortiLink Configuration: Verify the FortiLink configuration on the FortiGate. Ensure that the FortiLink interface is correctly set up and that all necessary settings are enabled.

  7. Check for Errors or Logs: Review the logs on both the FortiGate and FortiSwitches for any error messages or warnings that might provide additional insights into the issue.

  8. Restart Services: If the issue persists, consider restarting the switch-controller service on the FortiGate and the FortiSwitches to refresh the connections.

 

If these steps do not resolve the issue, consider reaching out to Fortinet support for further assistance.

Regards,

Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors