Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rcpdkc
Contributor II

Fortiswitch Multiport 3+

Hello, I have a 1101f series firewall. I want to connect 6 fortiswitches. When I connect the switches over fortilink by jumping from each other, there is no problem and all of them get ip and the connection status is actively monitored. However, when I need to connect with different 6 ports of the firewall (due to the wiring structure of the building), I enter 6 ports into fortilink. When I connect the switches, they get ip first, but the connections go immediately. DHCP does not work and they cannot get ip. What is the reason for this?

In addition, I created a fortilink port as a Hardware Switch. When I put the ports into it, all switches get ip but only 2 of them seem to be active. I can reach the others but they do not seem active. What could be the reason for this?

1 Solution
rcpdkc
Contributor II

The document I gave in the link gives all the details required for the connection.

https://community.fortinet.com/t5/FortiSwitch/Technical-Tip-How-to-Single-FortiGate-unit-manages-mul...

 

After applying the given document, it did not appear active except for 2 devices. Later, when I entered the fortiswitch interface, I saw that the time was incorrect. I entered the gateway address of the switches as ntp server and the time was corrected. Devices went online.

View solution in original post

13 REPLIES 13
AEK
SuperUser
SuperUser

Hello @rcpdkc 

Which firmware versions in firewall and switches?

AEK
AEK
rcpdkc
Contributor II

Fortios 7.0

AEK

What is the X in your FOS 7.0.X?

And what is the firmware version inside the FortiSwitches?

AEK
AEK
rcpdkc
Contributor II

Fortigate 7.0.14

Fortiswitch 7.0.4

AEK

In case you have "split interface" enabled on your FortiLink interface please try disable it and redo the test.

AEK
AEK
rcpdkc
Contributor II

I tried. The result is the same 

ebilcari
Staff
Staff

So the switches are not connected to each other and you want to terminate all their uplinks directly in FGT and configure them all to be in FortiLink mode?

If this what you are trying to achieve than this is not a common/recommended topology, you can refer to the topology section of the guide for more options, maybe consider some extra cabling.
NOTE: Using the hardware or software switch interface in FortiLink mode is not recommended in most cases. It can be used when the traffic on the ports is very light because all traffic across the switches moves through the FortiGate unit.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
rcpdkc

Actually, the topology I have given below is exactly what I want. However, it does not give any information about how to do it.

https://docs.fortinet.com/document/fortiswitch/7.4.2/fortilink-guide/801202/single-fortigate-unit-ma...

ebilcari

Than make sure you don't have any loop (switches should have only the uplink connected to FGT and the end hosts) and verify that STP is not disabling any of the ports. From the architecture of this model there should be no differences of the chosen ports when building the HW switch.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Labels
Top Kudoed Authors