fortiswitch-workshop-v1.5.3-handouts-lab · retail/enterprise: we are shipping fs -248d-fpoe and fs...

153
1

Upload: others

Post on 24-Mar-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

1

Page 2: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log
Page 3: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

3

Page 4: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

4

Page 5: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

5

Page 6: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

6

Page 7: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

PrimaryBenefits:✓ HighPortDensity

✓ IntegratedPowerOverEthernet

✓ ConnectAccessPoints,Peripherals,Cameras,Phones

✓ ManagedbyFortiGate- Createanintegrated,securenetwork

✓ LineRatePerformance

✓ LimitedLifetimeWarranty

7

Page 8: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

AllportsPOE+(FPOE)L2andPOE+oneveryportaremainrequirementsinRetail/Enterprise:WeareshippingFS-248D-fpoeandFS-548D-fpoe.AllportsPOE+capable

SecureInFortilink mode,eliminateneedtologintotheFortiSwitch.SecuremanagementchannelfromFortiGate.CentralVLANprovisioning.Centralizeduserauthentication.

CostOptimizedVerycompetitivepricing.Switch+opticalmodulesfromFortinet<50%ofcompetition.ReplacechassisandstackingsolutionsusingFortilink Stacking

CompletePortfolio1Gand10G/40GportdensitiesforRetail/Enterprise/DatacenterLayer2AccessmarketfocusReplacechassisandstackingsolutionsusinginnovativeFortilinkStacking

8

Page 9: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

9

Page 10: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

10

Page 11: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

11

Page 12: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

12

Page 13: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

13

Page 14: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

14

Page 15: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

15

Page 16: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

16

Page 17: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

17

Page 18: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

18

Page 19: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log
Page 20: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

WithFortiSwitchOSversion3.3.0andFortiOS5.4.0,allFSWDmodelssupportFortilinkwiththeFGmodelslistedinthetable.

*Roadmap:FGR-60D/FGR-90D/FG-300D/FG-70D/FG-80CM/FG-VM/FG-92D

20

Page 21: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

21

Page 22: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

22

Page 23: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Complete actionsrequiredincasedefaultconfig notbeingusedonFortiSwitch:1. PrepareFortiGate

enableswitchcontroller(CLI)– enabledbydefaultinmostmodels!configureinterfaceforFortilink(GUI– ifLAGthenCLI)

NTPandDHCPserversenabledautomaticallywhenusingGUI2. PrepareFortiSwitch

enableswitchcontroller(GUIorCLI)configureinterfaceforFortilink(CLI– enabledbydefault)

3. Connectcabling4. OnFGT,authorizeFSW

checkmanagedswitches,right-clicktoauthorize(GUI)

The followingconfigurationisoptional:5. ConfigureVLANs

createFortiSwitchVLANandassigntoFSWports(GUI)6. Enable802.1xportauthentication7.ManagePOEconfiguration

23

Page 24: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

24

Page 25: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

25

Page 26: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

26

Page 27: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

disconnectyourlaptop,it’snotnecessarytoaccessFSW

27

Page 28: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Initial Verfication:Fromyourlaptops:- PingFG-100Dunits- connecttoFG-100Dunits(SSHorGUI)– user:admin/password:<blank>

28

Page 29: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

MostFGmodelshaveswitch controller enabledbydefault,ifnotusethefollowingconfig:config systemglobalsetswitch-controllerenablesetswitch-controller-reserved-network169.254.254.0255.255.255.0end

29

Page 30: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Setmodeto“DedicatedtoExtensionDevice”IP addressing,NTPandDHCPserverconfigs areaddedautomatically

30

Page 31: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

UsingCLI,eachstep isdoneseparately:IPNTPDHCP

31

Page 32: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

UsingCLI,eachstep isdoneseparately:IPNTPDHCP

32

Page 33: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

UsingCLI,eachstep isdoneseparately:IPNTPDHCP

33

Page 34: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

FortiSwitch keepssendingFortilinkpacketstoFortiGate.

OnFortiGate,theFSWislistedin“ManagedSwitches”listwaitingforauthorization.

34

Page 35: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

FortiSwitch keepssendingFortilinkpacketstoFortiGate.

OnFortiGate,theFSWislistedin“ManagedSwitches”listwaitingforauthorization.

35

Page 36: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

FortiSwitch rebootsandjoins fortilink

36

Page 37: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

37

Page 38: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

38

Page 39: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Allportsareaddedtovlan “vsw.root”theIP/dhcp settings canbeconfigured

39

Page 40: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

40

Page 41: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

FSWIPcanbefoundintheDHCP monitorlist.

41

Page 42: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

FortilinkVLANid4094isusedforcommunicationbetweenFSWandFGTvlan id4074isusedbydefaultFortiSwitchVLAN

FS224D3Z14000202#showswitchinterfaceconfig switchinterfaceedit"port1"setnative-vlan4074

nextedit"port2"setnative-vlan4074

nextedit"port3"setnative-vlan4074

nextedit"port4"setnative-vlan4074

nextedit"port5"setnative-vlan4074

next

42

Page 43: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

edit"port6"setnative-vlan4074

nextedit"port7"setnative-vlan4074

nextedit"port8"setnative-vlan4074

nextedit"port9"setnative-vlan4074

nextedit"port10"setnative-vlan4074

nextedit"port11"setnative-vlan4074

nextedit"port12"setnative-vlan4074

nextedit"port13"setnative-vlan4074

nextedit"port14"setnative-vlan4074

nextedit"port15"setnative-vlan4074

nextedit"port16"setnative-vlan4074

nextedit"port17"setnative-vlan4074

nextedit"port18"setnative-vlan4074

nextedit"port19"setnative-vlan4074

nextedit"port20"setnative-vlan4074

42

Page 44: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

nextedit"port21"setdynamic-fortilink-modeenable

nextedit"port22"setdynamic-fortilink-modeenable

nextedit"port23"setdynamic-fortilink-modeenable

nextedit"port24"setdynamic-fortilink-modeenable

nextedit"internal"setnative-vlan4094setstp-statedisabled

nextend

42

Page 45: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

It’sonlynecessarytosaveFGTconfiguration, itincludestheconfigurationofthemanagedswitches.

usethefortigate gui orcli,FGT#execssh [email protected]

FSW#execfactoryreset

43

Page 46: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

44

Page 47: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

45

Page 48: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

46

Page 49: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

47

Page 50: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log
Page 51: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

connectport21oneach FSWtothecorrespondingportintheFG-100D-1Fortilinkwillbeestablishedusingthesinglelinkbetweenthedevices

49

Page 52: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

EachFSWdeviceisconnectedwith2x1Gports(port21andport22)tooneFortiGate(FG-100D-HA1)and2x1Gports(port23andport24)totheother(FG-100D-HA2)Example:

FS-224D-POE-1port21 port1FG-100D-HA1port22 port2FG-100D-HA1port23 port1FG-100D-HA2port24 port2FG-100D-HA2

DISCONNECTcablefromFSW,theconfigurationisdoneviaFGT

50

Page 53: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

FortiGateisconfiguredwithHAinactive-passivemode,withsessionsynchronizationenabled.Overrideisdisabledtofacilitatetesting.

ModelsinHApairmustbeidenticaleveninhardwarerev

51

Page 54: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

52

Page 55: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

53

Page 56: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

54

Page 57: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

FortiSwitch keepssendingFortilinkpacketstoFortiGate.

OnFortiGate,theFSWislistedin“ManagedSwitches”listwaitingforauthorization.

55

Page 58: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

56

Page 59: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

57

Page 60: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

58

Page 61: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

lagbalancing basedonIPsrc anddst

59

Page 62: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

connectto FortiSwitch viatheFortiGate#execssh [email protected]

60

Page 63: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

connectto FortiSwitch viatheFortiGate#execssh [email protected]

61

Page 64: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

All4fortilinkportsareenabled:port21,22,23and24

FS224D3Z14000202#showswitchinterfaceconfig switchinterfaceedit"port1"setnative-vlan4074

nextedit"port2"setnative-vlan4074

nextedit"port3"setnative-vlan4074

nextedit"port4"setnative-vlan4074

nextedit"port5"setnative-vlan4074

nextedit"port6"

62

Page 65: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

setnative-vlan4074nextedit"port7"setnative-vlan4074

nextedit"port8"setnative-vlan4074

nextedit"port9"setnative-vlan4074

nextedit"port10"setnative-vlan4074

nextedit"port11"setnative-vlan4074

nextedit"port12"setnative-vlan4074

nextedit"port13"setnative-vlan4074

nextedit"port14"setnative-vlan4074

nextedit"port15"setnative-vlan4074

nextedit"port16"setnative-vlan4074

nextedit"port17"setnative-vlan4074

nextedit"port18"setnative-vlan4074

nextedit"port19"setnative-vlan4074

nextedit"port20"setnative-vlan4074

next

62

Page 66: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

edit"port21"setdynamic-fortilink-modeenable

nextedit"port22"setdynamic-fortilink-modeenable

nextedit"port23"setdynamic-fortilink-modeenable

nextedit"port24"setdynamic-fortilink-modeenable

nextedit"internal"setnative-vlan4094setstp-statedisabled

nextend

62

Page 67: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

It’sonlynecessarytosaveFGTconfiguration, itincludestheconfigurationofthemanagedswitches.

63

Page 68: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

64

Page 69: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

65

Page 70: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

66

Page 71: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

EachFSWdeviceisconnectedwith2x1Gports(port21andport22)tooneFortiGate(FG-100D-HA1)and2x1Gports(port23andport24)totheother(FG-100D-HA2)Example:

FS-224D-POE-1port21 port1FG-100D-HA1port22 port2FG-100D-HA1port23 port1FG-100D-HA2port24 port2FG-100D-HA2

afterthevlans areconfigured,usethecableagainandconnecttotheFSWuserport.

67

Page 72: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

68

Page 73: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Usetheinformationprovided intheaddressingtable.

69

Page 74: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

70

Page 75: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

71

Page 76: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

72

Page 77: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

First3stepsdoneatonce: VLAN,IPaddressandDHCPserver

73

Page 78: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

First3stepsdoneatonce: VLAN,IPaddressandDHCPserver

HoldCtrlkeytoselectmultipleportsthatarenon-contiguous

74

Page 79: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Thereshouldbeatleastapolicyallowingtrafficbetweenyourvlans andtheothers,andasecondpolicytoallowtrafficfromyourvlan totheservers

servers:172.16.1.160-172.16.1.165

75

Page 80: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

servers:172.16.1.160-172.16.1.165

76

Page 81: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

77

Page 82: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

78

Page 83: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

79

Page 84: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

1.createthevlan thatisgoingtoreceivetaggedtrafficFG-100D-HA1#showswitch-controllervlan vlan-voipconfig switch-controllervlanedit"vlan-voip"setvlanid 50setcolor25

nextend

2.ConfigureIPaddressingandDHCPserverFG-100D-HA1#showsysteminterfacevlan-voipconfig systeminterfaceedit"vlan-voip"setvdom "root"setip 10.10.50.1255.255.255.0setallowaccess pinghttpssshsettypeswitch-vlansetsnmp-index21setmacaddr 08:5b:0e:de:77:d0

next

80

Page 85: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

end

FG-100D-HA1#showsystemdhcp server5config systemdhcp serveredit5setdns-servicedefaultsetdefault-gateway10.10.50.1setnetmask255.255.255.0setinterface"vlan-voip"config ip-rangeedit1setstart-ip 10.10.50.2setend-ip 10.10.50.254

nextend

nextend

3.ConfigureFSWporttoallowthisVLAN:config switch-controller managed-switch

edit "FS224D3Z14000202"config ports

edit "port11"set allowed-vlans “vlan-voip”

next end

nextend

80

Page 86: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

81

Page 87: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

82

Page 88: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

83

Page 89: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

84

Page 90: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

EachFSWdeviceisconnectedwith2x1Gports(port25andport26)totheFortiGate

85

Page 91: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Configurationrequiredfor802.1xauthentication:

1.Configureuser/usergrouponFortiGate (alreadypreparedfortheworkshop)Forsimplicity,userisdefinedlocallyonFortiGate,howeveritcouldalsouse

externalservers

2.Enable802.1xauthenticationonFortiSwitchVLAN=>FortiSwitchportsautomaticallyenabled

When802.1xisenabledontheFortiSwitchVLAN,allportsthatareassignedtothatFortiSwitchVLANareautomaticallyenabledfor802.1xauthentication

802.1xstatuscanbeverifiedusingthecommand:FG-100D-HA1#config switch-controllermanaged-switch

FG-100D-HA1(managed-switch)#editFS224D3Z14000202

FG-100D-HA1(FS224D3Z14000202)#FG-100D-HA1(FS224D3Z14000202)#config ports

FG-100D-HA1(ports)#

86

Page 92: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

FG-100D-HA1(ports)#FG-100D-HA1(ports)#editport9

FG-100D-HA1(port9)#getport-name:port9switch-id:FS224D3Z14000202speed:autostatus:updot1x-enable:enabledot1x-status:authenticatingvlan :vlan100allowed-vlans:

86

Page 93: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

87

Page 94: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

88

Page 95: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

89

Page 96: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

InWindows clients,enable802.1xinthenetworkadapterpropertiesuncheck“Remembermycredentials….”sothatyougettheuser/pwd

promptineveryconnectionattempt

InAdvancedSettings,choosetospecifyauthenticationmodeas“Userauthentication”

90

Page 97: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Afterchanging adaptersettings,orwhentheadapterisdisabled/enabled,orwhenthecableinunplugged/plugged,theusergetsthecredentialspopup

91

Page 98: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

92

Page 99: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

93

Page 100: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

94

Page 101: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

95

Page 102: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

96

Page 103: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

EachFSWdeviceisconnectedwith2x1Gports(port25andport26)totheFortiGate.

97

Page 104: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

98

Page 105: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

toresetaPOEportusingCLI,runthefollowingcommand:executeswitch-controllerpoe-reset<switchSN><port>

99

Page 106: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

100

Page 107: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

101

Page 108: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

102

Page 109: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

103

Page 110: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

EachFSWdeviceisconnectedwith2x1Gports(port25andport26)totheFortiGate.

104

Page 111: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Thespeakerwilladd“office”FortiSwitchVLAN,IPandDHCPserver;andconfigureSSID

ThedelegateswillassigntheirportstothisFortiSwitchVLAN,andonevolunteerwillauthorizetheAP

FG-100D-HA1#showswitch-controllervlanofficeconfig switch-controllervlanedit"office"next

end

FG-100D-HA1#showsysteminterfaceofficeconfig systeminterfaceedit"office"setvdom "root"setip 10.10.60.1255.255.255.0setallowaccess pinghttpsssh capwapsettypeswitch-vlansetsnmp-index22setmacaddr 08:5b:0e:de:77:d0

105

Page 112: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

nextend

FG-100D-HA1#showsystemdhcp server6config systemdhcp serveredit6setdns-servicedefaultsetdefault-gateway10.10.60.1setnetmask255.255.255.0setinterface"office"config ip-rangeedit1setstart-ip 10.10.60.2setend-ip 10.10.60.254

nextend

settimezone-optiondefaultnext

end

config switch-controllermanaged-switchedit"FS224D3Z14000202"setfsw-wan1-peer"fortilinkFSW1"setfsw-wan1-adminenableconfig portsedit"port1"setvlan "office"

nextedit"port2"setvlan "office"

nextedit"port3"setvlan "office"

nextedit"port4"setvlan "office"

nextedit"port5"setvlan "office"

nextedit"port6"setvlan "office"

nextedit"port7"

105

Page 113: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

setvlan "office"nextedit"port8"setvlan "office"

nextedit"port9"setvlan "office"

nextedit"port10"setvlan "office"

nextedit"port11"setvlan "office"

nextedit"port12"setvlan "office"

nextedit"port13"setvlan "office"

nextedit"port14"setvlan "office"

nextedit"port15"setvlan "office"

nextedit"port16"setvlan "office"

nextedit"port17"setvlan "office"

nextedit"port18"setvlan "office"

nextedit"port19"setvlan "office"

nextedit"port20"setvlan "office"

nextedit"port21"setvlan “vsw.root"

next

105

Page 114: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

edit"port22"setvlan "vsw.root"

nextedit"port23"setvlan "vsw.root"

nextedit"port24"setvlan "vsw.root"

nextend

nextend

105

Page 115: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

106

Page 116: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

107

Page 117: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Usethefollowing commandtoauthorizeyourFAP,makesuretoincludethecorrectserialnumber:config wireless-controller wtp

edit "FAP24D3X15000029"set admin enable

nextend

108

Page 118: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

109

Page 119: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

110

Page 120: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

111

Page 121: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

SSIDsareassignedtotheFAPusingdifferentVLANs:VLAN110:GuestSSIDVLAN120:OfficeVLAN130:Customers

PoliciesarecreatedonFGTtocontroltrafficbetweentheSSIDs.

112

Page 122: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

113

Page 123: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

114

Page 124: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

115

Page 125: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

116

Page 126: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

117

Page 127: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

D-series FortiSwitchEnhancedsoftwareroadmapAllmodelssupportFortilinkmode

AllportsPOE+(FPOE)L2andPOE+oneveryportaremainrequirementsinRetail/EnterpriseNewmodelsshippingFS-224D-FPOEandFS-548D-FPOE

SecureInFortilinkmode,eliminatelogintoFortiSwitch.AllcontrolsfromFortiGate.CentralVLANprovisioningCentralizeduserauthentication

CostOptimizedVerycompetitivepricing.Switch+opticalmodulesfrom

118

Page 128: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Fortinet<50%ofcompetition.NewmodelshavenewSupportSKUpricingReplacechassisandstackingsolutionsusingFortilink Stacking

TheFortilink technologytomanageswitchingfromafirewallisuniqueintheindustryAbilitytomanageanetworkfromacentralcontrolleriswhatSDNpromisesConfiguringSecurityprofilesonanetworkinasimplemannerisvaluable

SecuritymanagementfromFortiGate consoleFAPandFSWareportextensionsofFortigateUnifiedsecuritypoliciesforwiredorwirelessconnections

118

Page 129: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

119

Page 130: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

120

Page 131: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

121

Page 132: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Initial Verfication:Fromyourlaptops:- PingFG-100Dunits- connecttoFG-100Dunits(SSHorGUI)– user:admin/password:<blank>

122

Page 133: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Initial Verfication:Fromyourlaptops:- Ping FG-100Dunits- connecttoFG-100Dunits(SSHorGUI)– user:admin/password:<blank>

123

Page 134: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

124

Page 135: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

[root@centos-client-1~]#ssh [email protected]#getsystemstatusVersion:FortiSwitch-224D-POEv3.3.0,build0112,150612(Interim)Serial-Number:FS224D3Z14000202BIOSversion:04000002SystemPart-Number:P15455-01BurninMAC:08:5b:0e:5e:3e:4cHostname:FS224D3Z14000202Distribution:InternationalBranchpoint:112Systemtime:WedDec3116:03:231969

FS224D3Z14000202#getsystemglobaladmin-concurrent:enableadmin-https-pki-required:disableadmin-lockout-duration:60admin-lockout-threshold:3admin-maintainer:enableadmin-port:80admin-scp :disable

125

Page 136: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

admin-server-cert:self-signadmin-sport:443admin-ssh-grace-time:120admin-ssh-port:22admin-ssh-v1:disableadmin-telnet-port:23admintimeout :5allow-subnet-overlap:disablecfg-save:automaticcsr-ca-attribute:enabledaily-restart:disabledetect-ip-conflict:enabledst :enablegui-lines-per-page:50hostname:FS224D3Z14000202language:englishldapconntimeout :500log-user-in-upper:disableradius-port:1812refresh:0registration-notification:enableremoteauthtimeout :5revision-backup-on-logout:enableservice-expire-notification:enablestrong-crypto:disableswitch-mgmt-mode:localtimezone :(GMT-8:00)PacificTime(US&Canada)user-server-cert:self-sign

125

Page 137: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Browsetohttp://192.168.1.99user:adminpassword:<blank>

126

Page 138: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Checkswitchconfiguration,note thatallportsareinthesameVLAN(vlan-id1)bydefault#showswitchinterface#config switchinterface#editport##get

Andports21to24areenabledforautodiscoverybyFortilink

127

Page 139: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

Checkswitchconfiguration,note thatallportsareinthesameVLAN(vlan-id1)bydefault#showswitchinterface#config switchinterface#editport##get

Andports21to24areenabledforautodiscoverybyFortilink

128

Page 140: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

129

Page 141: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log
Page 142: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log
Page 143: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log
Page 144: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log
Page 145: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log
Page 146: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log
Page 147: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

136

Page 148: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

137

Page 149: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

138

Page 150: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

139

Page 151: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

140

Page 152: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

141

Page 153: FortiSwitch-Workshop-v1.5.3-Handouts-Lab · Retail/Enterprise: We are shipping FS -248D-fpoe and FS -548D-fpoe. All ports POE+ capable Secure In Fortilinkmode, eliminate need to log

142