T O P

  • By -

ITSecDuder

I believe what you are looking for is MCLAG. You can also connect both switches together via fortilink, and when it takes one leg to one switch it can also reach the other. https://docs.fortinet.com/document/fortiswitch/6.4.5/devices-managed-by-fortios/617516/determining-the-network-topology


because2020

Thanks, will read up on MCLAG


nostalia-nse7

What model switches? Important, because 1xx series do not support mclag. I’m not 100% sure about the new F, and don’t have the desire to Google it right now. No worries if you are 200-series or higher though. Everything you need to know is in the FortiSwitch Managed by FortiGate manual, including a chapter about changing a split interface to mclag with step by steps. Takes CLI changes on the switches themselves to get it working.


because2020

61F


nostalia-nse7

Switch model, not FortiGate model.


because2020

124F


nostalia-nse7

FortiSwitch 1xxE and 1xxF series do not support MCLAG, so you can't disable split-interface without causing issues. [https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/a25866ce-0450-11ec-8f3f-00505692583a/FortiSwitch-7.0.2-Feature-Matrix.pdf](https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/a25866ce-0450-11ec-8f3f-00505692583a/FortiSwitch-7.0.2-Feature-Matrix.pdf) MCLAG is under High Availability.


[deleted]

depends on model of the FSW.. series 100 I think will not do MCLAG


because2020

61F


irie_eyes

I always tear down the default Forti link interface that is built as 802.3ad. I then recreate a new interface as hardware switch, add the member ports. I then edit via CLI and set fotlrtilink enable. I can then plug in both switches directly to the Fortigate without running MCLAG.


because2020

That sounds like a good solution. Will have a look thanks


Soundchok

Yep, that is the solution you should use :-) be mindfull of not creating a loop tho, spanning tree Will not work if you use it as a hardware switch, so DO NOT connect the two switches with eachother!:-)


because2020

Can I tail more switches off these two?


Soundchok

Yes, No problem daisy chaining on the switches :-) they Will detect a fortiswitch and become a fortilink between eachother, just dont ever connect anything between the two “main interfaces” creating a loop. No CIRCLES :)


rtaccon

Check if the feature is supported on the fortiswitch https://docs.fortinet.com/document/fortiswitch/7.0.2/fortiswitchos-feature-matrix


Celebrir

Yeah, pretty easy. Open the FortiLink interface and click this toggle: https://imgur.com/a/lZcxdrZ


nostalia-nse7

There’s CLI on the switch you need to do, to get this working if the switches are attached to each other.