Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
claydawg
New Contributor II

Same VLAN on Multiiple Fortilink Interfaces

I have a scenario where there are two different Fortilink interfaces on a FortiGate. I need to extend a particular VLAN from the gate to both Fortilink-managed switches. Unfortunately this requires me to require a VLAN sub-interface on each Fortilink interface. One has an IP address configured and the other is just 0.0.0.0/0. I assumed, maybe incorrectly, that this would just do 802.1q and pass layer-2 between interfaces but I also know this is a firewall and that sort of behavior may not work. Can anyone confirm if this is supported? If not, is the only solution to re-architect this and reconfigure for only a single Fortilink?

8 REPLIES 8
Stephen_G
Moderator
Moderator

Hello claydawg,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen - Fortinet Community Team
Stephen_G
Moderator
Moderator

Hello claydawg,

 

This document may help you with what you need: https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/454200/multiple-fortiswitches-managed-v...

 

Let me know if you need further help, or feel free to contact us.

 

Kind regards,

Stephen - Fortinet Community Team
claydawg
New Contributor II

Thanks, Stephen. Unfortunately I don't see anything in that docs that answers my question. I'm really hoping there is a way to make this work. I just don't see the value in FortiLink. It seems like it just makes traditional networking more difficult and restrictive.

hbac
Staff
Staff

Hi @claydawg,  

 

I would suggest configuring only a single fortilink to manage both switches. 

 

Regards, 

claydawg
New Contributor II

Thanks. This is a huge drawback of FortiLink. I understand the simplicity of it, but it really limits your ability to customize the network after the fact.

AEK

Hi @claydawg 

  • Are your FSW interconnected? Do they need to be interconnected?
  • Do your FSW support ICL or ISL?
  • Why do you need to the VLAN to both FSW?
  • Why you need to use 2 FortiLinks?

If you elaborate a bit more maybe we can help.

AEK
AEK
claydawg
New Contributor II

Why do I need to extend the same VLAN to two different switches? I can't even believe I'm being asked that question. I don't mean to be rude but this is a common practice on any network. There's no need to justify the necessity.

AEK

Depending on your design requirements this is what you may need.

https://docs.fortinet.com/document/fortiswitch/7.4.2/fortilink-guide/801202/single-fortigate-unit-ma...

By setting FortiLink over HW/SW switch should allow you via one FortiLink to have the same VLAN(s) propagated to both FSW and the same gateway visible from the managed switches.

AEK
AEK
Labels
Top Kudoed Authors