Hot!Can you mix modes on a FortiSwitch? Managed by FG, but with customization through CLI?

Author
ehenvironments
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/01/03 05:55:57
  • Status: offline
2019/08/12 15:50:56 (permalink)
0

Can you mix modes on a FortiSwitch? Managed by FG, but with customization through CLI?

I have used FortiSwitches in a couple locations, but always managed by a FG. 
 
I will have a need at a location soon for some advanced configuration to support IP Video traffic on one of the VLANs, but features like IGMP Snooping and Querier don't seem to be exposed in the FG interface.  Can you configure these settings through CLI while still being managed by the FG, or does FG management effectively wipe the configuration and load its own from the FG? 
 
If you can do both, can you configure with CLI at any time while connected to the FG, or only before or after adding it to the FG as a managed switch?
 
TIA,
 
-David
#1

4 Replies Related Threads

    SecurityPlus
    Gold Member
    • Total Posts : 287
    • Scores: 4
    • Reward points: 0
    • Joined: 2014/08/11 18:41:34
    • Status: offline
    Re: Can you mix modes on a FortiSwitch? Managed by FG, but with customization through CLI? 2019/08/12 22:28:32 (permalink)
    0
    I would be curious to hear an answer to this as well .

    FWF30E, FG50E, FWF50E, FG60D, FWF60D, FG60E, FG80E, FG100D
    FortiOS 5.2, 5.4, 5.6, and 6.0
    FortiSwitch FS-224E-POE
    FAP-221E, FAP-221C
    #2
    tanr
    Platinum Member
    • Total Posts : 697
    • Scores: 31
    • Reward points: 0
    • Joined: 2016/05/09 17:09:43
    • Status: offline
    Re: Can you mix modes on a FortiSwitch? Managed by FG, but with customization through CLI? 2019/08/13 07:54:46 (permalink)
    0
    With the 3.6.x switch OS you could make some changes in the CLI after the switch became managed that stayed between firmware updates.  The one I used the most was setting switch ports to have discard-mode all-tagged.  Note that you can now set discard-mode from the FortiGate with 6.0.x, and upgrading to the 6.0.x firmware wiped my discard-mode settings on 1 of our 6 switches (a 124E).
     
    Note that IGMP Snooping is supposed to be supported on managed FortiSwitches above 1xxE models, though release notes still list some bugs.
    #3
    Duncan
    New Member
    • Total Posts : 17
    • Scores: 2
    • Reward points: 0
    • Joined: 2018/09/11 20:10:29
    • Status: offline
    Re: Can you mix modes on a FortiSwitch? Managed by FG, but with customization through CLI? 2019/09/02 18:26:27 (permalink)
    0
    ehenvironments
    ...or does FG management effectively wipe the configuration and load its own from the FG? 

    Yes, if you configure the switch via the FS CLI, your custom config will get wipe after making changes on the FG.
    The proper way to do this is in the FG CLI. Use the commands 'config switch-controller managed-switch', 'edit <FS serial number>' then 'config igmp-snooping'.
    #4
    ehenvironments
    New Member
    • Total Posts : 4
    • Scores: 0
    • Reward points: 0
    • Joined: 2014/01/03 05:55:57
    • Status: offline
    Re: Can you mix modes on a FortiSwitch? Managed by FG, but with customization through CLI? 2019/09/02 19:26:33 (permalink)
    0
    Excellent, thanks for the insight.  We will give it a try.
    #5
    Jump to:
    © 2019 APG vNext Commercial Version 5.5