Fortinet white logo
Fortinet white logo

Introduction

Introduction

This document provides the following information for FortiSwitch 7.4.1 devices managed by FortiOS 7.4.1 build 2463:

See the Fortinet Document Library for FortiSwitchOS documentation.

Refer to the FortiLink Compatibility table to find which FortiSwitchOS versions support which FortiOS versions.

NOTE: FortiLink is not supported in transparent mode.

The maximum number of supported FortiSwitch units depends on the FortiGate model:

FortiGate Model Range Number of FortiSwitch Units Supported
FortiGate 40F, FortiGate-VM01 8
FortiGate 6xE, 8xE, 90E, 91E 16

FGR-60F, FG-60F, FGR-60F-3G4G, FG-61F, FGR-70F, FGR-70F-3G4G, FG-80F, FG-80FB, FG-80FP, FG-81F, and FG-81FP

24

FortiGate 100D, FortiGate-VM02 24
FortiGate 100E, 100EF, 100F, 101E, 140E, 140E-POE 32
FortiGate 200E, 201E 64
FortiGate 300D to 500D 48
FortiGate 300E to 500E 72
FortiGate 600D to 900D and FortiGate-VM04 64
FortiGate 600E to 900E 96
FortiGate 1000D to 15xxD 128
FortiGate 1100E to 26xxF 196

FortiGate-3xxx and up and FortiGate-VM08 and up

300

note icon New models (NPI releases) might not support FortiLink. Contact Customer Service & Support to check support for FortiLink.

What’s new in FortiOS 7.4.1

The following list contains new managed FortiSwitch features added in FortiOS 7.4.1:

  • You can now make your Security Fabric more secure with the FortiLink secured fabric. The FortiLink secured fabric provides authentication and encryption to all fabric links, wherever possible. Zero-touch support is available for FortiLink mode over a layer-2 network and over a layer-3 network.

  • More tests have been added to the FortiSwitch recommendations to help optimize your network:

    • When a connected tier-1 multichassis link-aggregation group (MCLAG) peer group is detected and FortiOS detects a possible tier-2 MCLAG pair of switches, FortiOS recommends forming a tier-2 MCLAG.

    • When a connected tier-2 MCLAG peer group is detected and FortiOS detects a possible tier-3 MCLAG pair of switches, FortiOS recommends forming a tier-3 MCLAG.

  • You can now enable or disable the locking down of inter-switch links (ISLs) on a single FortiLink interface in the Edit FortiLink Interface page (WiFi & Switch Controller > FortiLink Interface).

  • The FortiOS switch controller now supports the synchronization of the FortiGate system interface description to the switch VLAN description (up to the first 63 characters of FortiSwitch VLAN description field in FortiOS). This allows a more flexible use of the Tunnel-Private-Group-Id RADIUS attribute.

  • The CLI commands for configuring Precision Time Protocol (PTP) transparent-clock mode have changed. FortiOS supports the previous CLI commands, as well as the new ones.

  • A new CLI command controls whether intra-VLAN traffic is blocked or allowed when the connection to the FortiGate device is lost. Before FortiOS 7.4.1, intra-VLAN traffic on the managed FortiSwitch units was blocked when the connection to the FortiGate device is lost.

  • Managed FortiSwitch VLANs can now mirror traffic on a client, and the FortiGate device will analyze the remote traffic.

  • Managed FortiSwitch units can now perform inter-VLAN routing. The FortiGate device can program a FortiSwitch unit to do the layer-3 routing of trusted traffic between specific VLANs.

  • When using FortiLink mode over a layer-3 network and DHCP discovery with DHCP option 138, the top FortiSwitch unit (with the _FlinkDhcpDisc_ trunk) will now automatically have a Spanning Tree Protocol (STP) priority of 24576, instead of an STP priority of 32768.

Introduction

Introduction

This document provides the following information for FortiSwitch 7.4.1 devices managed by FortiOS 7.4.1 build 2463:

See the Fortinet Document Library for FortiSwitchOS documentation.

Refer to the FortiLink Compatibility table to find which FortiSwitchOS versions support which FortiOS versions.

NOTE: FortiLink is not supported in transparent mode.

The maximum number of supported FortiSwitch units depends on the FortiGate model:

FortiGate Model Range Number of FortiSwitch Units Supported
FortiGate 40F, FortiGate-VM01 8
FortiGate 6xE, 8xE, 90E, 91E 16

FGR-60F, FG-60F, FGR-60F-3G4G, FG-61F, FGR-70F, FGR-70F-3G4G, FG-80F, FG-80FB, FG-80FP, FG-81F, and FG-81FP

24

FortiGate 100D, FortiGate-VM02 24
FortiGate 100E, 100EF, 100F, 101E, 140E, 140E-POE 32
FortiGate 200E, 201E 64
FortiGate 300D to 500D 48
FortiGate 300E to 500E 72
FortiGate 600D to 900D and FortiGate-VM04 64
FortiGate 600E to 900E 96
FortiGate 1000D to 15xxD 128
FortiGate 1100E to 26xxF 196

FortiGate-3xxx and up and FortiGate-VM08 and up

300

note icon New models (NPI releases) might not support FortiLink. Contact Customer Service & Support to check support for FortiLink.

What’s new in FortiOS 7.4.1

The following list contains new managed FortiSwitch features added in FortiOS 7.4.1:

  • You can now make your Security Fabric more secure with the FortiLink secured fabric. The FortiLink secured fabric provides authentication and encryption to all fabric links, wherever possible. Zero-touch support is available for FortiLink mode over a layer-2 network and over a layer-3 network.

  • More tests have been added to the FortiSwitch recommendations to help optimize your network:

    • When a connected tier-1 multichassis link-aggregation group (MCLAG) peer group is detected and FortiOS detects a possible tier-2 MCLAG pair of switches, FortiOS recommends forming a tier-2 MCLAG.

    • When a connected tier-2 MCLAG peer group is detected and FortiOS detects a possible tier-3 MCLAG pair of switches, FortiOS recommends forming a tier-3 MCLAG.

  • You can now enable or disable the locking down of inter-switch links (ISLs) on a single FortiLink interface in the Edit FortiLink Interface page (WiFi & Switch Controller > FortiLink Interface).

  • The FortiOS switch controller now supports the synchronization of the FortiGate system interface description to the switch VLAN description (up to the first 63 characters of FortiSwitch VLAN description field in FortiOS). This allows a more flexible use of the Tunnel-Private-Group-Id RADIUS attribute.

  • The CLI commands for configuring Precision Time Protocol (PTP) transparent-clock mode have changed. FortiOS supports the previous CLI commands, as well as the new ones.

  • A new CLI command controls whether intra-VLAN traffic is blocked or allowed when the connection to the FortiGate device is lost. Before FortiOS 7.4.1, intra-VLAN traffic on the managed FortiSwitch units was blocked when the connection to the FortiGate device is lost.

  • Managed FortiSwitch VLANs can now mirror traffic on a client, and the FortiGate device will analyze the remote traffic.

  • Managed FortiSwitch units can now perform inter-VLAN routing. The FortiGate device can program a FortiSwitch unit to do the layer-3 routing of trusted traffic between specific VLANs.

  • When using FortiLink mode over a layer-3 network and DHCP discovery with DHCP option 138, the top FortiSwitch unit (with the _FlinkDhcpDisc_ trunk) will now automatically have a Spanning Tree Protocol (STP) priority of 24576, instead of an STP priority of 32768.