FortiSwitch Managed By FortiOS 6 – Introduction

Supported models

Introduction

NOTE: FortiLink is not supported in Transparent mode.

The maximum number of supported FortiSwitch units depends on the FortiGate model:

 

FortiGate Model Range
 

Number of FortiSwitch Units Supported

Up to FortiGate-98 and FortiGate-VM01                                8

FortiGate-100 to 280 and FortiGate-VM02                             24

FortiGate-300 to 5xx                                                           48

FortiGate-600 to 900 and FortiGate-VM04                             64

FortiGate-1000 and up                                                        128

FortiGate-3xxx and up and FortiGate-VM08 and up                300

Supported models

The following table shows the FortiSwitch models that support FortiLink mode when paired with the corresponding FortiGate models and the listed minimum software releases. For example, the FGT-500E model with FortiOS 5.6.3 and later supports all FortiSwitch D-series and E-series models running FortiSwitchOS 3.6.0 and later.

Each row includes support for earlier FortiGate models. For example, the FGT-500E row includes support by the FortiGate models in the rows above it.

    FortiSwitch Models
FortiGate and FortiWiFi Models Earliest FortiOS
FGT-90D 5.2.2 FS-224D-POE

Supported models

 
FortiGate and FortiWiFi Models Earliest FortiOS FortiSwitch Models
FGT-60D

FGT-100D, 140D, 140D-POE, 140D-T1

FGT-200D, 240D, 280D, 280D-POE

FGT-600C

FGT-800C

FGT-1000C, 1200D, 1500D

FGT-3700D, FGT-3700DX

5.2.3 FSR-112D-POE

FS-108D-POE

FS-124D (POE)

FS-224D-POE and FPOE

5.4.0 All FortiSwitch D-series models.

FortiSwitchOS 3.3.x or 3.4.0 is recommended.

FGT and FWF-30D, 30D-POE, 30E

FGT and FWF-50E, 51E

FGR-60D

FGT-70D, 70D-POE

FGT-80D

FGR-90D

FGT and FWF-92D

FGT-94D-POE, 98D-POE

FGT-300D

FGT-400D

FGT-500D

FGT-600D

FGT-900D

FGT-1000D

FGT-3000D, 3100D, 3200D, 3240C, 3600C,

3810D, 3815D

FGT_VM, VM64, VM64-AWS, VM64AWSONDEMAND, VM64-HV, VM64-KVM, VMVMX, VM64-XEN

5.4.1 All FortiSwitch D-series models.

FortiSwitchOS 3.4.2 or later is required for all managed switches.

FGT and FWF- 60E, 61E FGT-100E, 101E 5.4.2 All FortiSwitch D-series models.

FortiSwitchOS 3.4.2 or later is required for all managed switches.

FGT-80E, 80E-POE, 81E, 81E-POE FGT-100EF 5.4.3 All FortiSwitch D-series models.

FortiSwitchOS 3.4.2 or later is required for all managed switches.

FGT-90E, 91E

FGT-200E, 201E

FGT-2000E, 2500E

5.6.0 All FortiSwitch D-series models.

FortiSwitchOS 3.5.4 or later is required for all managed switches.

Support of FortiLink features

    FortiSwitch Models
FortiGate and FortiWiFi Models Earliest FortiOS
FGT-500E 5.6.3 All FortiSwitch D-series and E-series models.

FortiSwitchOS 3.6.0 or later is required for all managed switches.

Support of FortiLink features

The following table lists the FortiSwitch models supported by FortiLink features.

FortiLink Features FortiSwitch Models
Centralized VLAN Configuration D-series, E-series
Switch POE Control D-series, E-series
Link Aggregation Configuration D-series, E-series
Spanning Tree Protocol (STP) D-series, E-series
LLDP/MED D-series, E-series
IGMP Snooping Not supported on 112D-POE, 1xxE-Series
802.1x Authentication (Port-based, MAC-based, MAB) D-series, E-series
Syslog Collection D-series, E-series
DHCP Snooping Not supported on 1xxE-Series
Device Detection D-series, E-series
Support FortiLink FortiGate in HA Cluster D-series, E-series
LAG support for FortiLink Connection D-series, E-series
Active-Active Split MLAG from FortiGate to FortiSwitch units for Advanced Redundancy Not supported on FS-1xx Series
sFlow Not supported on 1xxE-Series
Dynamic ARP Inspection (DAI) Not supported on 1xxE-Series
Port Mirroring D-series, E-series

Before you begin

FortiLink Features FortiSwitch Models
RADIUS Accounting Support Not supported on 1xxE-Series
Centralized Configuration D-series, E-series
Access VLAN Not supported on 1xxE-Series, 112D-POE
STP BDPU Guard, Root Guard, Edge Port D-series, E-series
Loop Guard D-series, E-series
Switch admin Password D-series, E-series
Storm Control D-series, E-series
802.1x-Authenticated Dynamic VLAN Assignment D-series, E-series
Host Quarantine on Switch Port Not supported on 1xxE Series, 112D-POE
QoS Not supported on 1xxE-Series, 112D-POE
Centralized Firmware Management D-series, E-series

Before you begin

Before you configure the managed FortiSwitch unit, the following assumptions have been made in the writing of this manual:

  • You have completed the initial configuration of the FortiSwitch unit, as outlined in the QuickStart Guide for your FortiSwitch model, and you have administrative access to the FortiSwitch web-based manager and CLI.
  • You have installed a FortiGate unit on your network and have administrative access to the FortiGate web-based manager and CLI.

How this guide is organized

This guide contains the following sections:

  • Whatʼs new in FortiOS 6.0 describes the new features for this release. l Connecting FortiLink ports describes how to connect FortiSwitch ports to FortiGate ports. l FortiLink configuration using the FortiGate GUI describes how to use the FortiGate GUI for FortiLink configuration. l FortiLink configuration using the FortiGate CLI describes how to use the FortiGate CLI for FortiLink configuration. l Network topologies for managed FortiSwitch units describes the configuration for various network topologies.
  • Optional setup tasks describes other setup tasks that are optional. l FortiSwitch features configuration describes how to configure managed FortiSwitch features, including VLANs. l FortiSwitch port features describe how to configure ports and PoE from the FortiGate unit.

 


Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

This entry was posted in Administration Guides, FortiOS 6, FortiSwitch on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.