Fortinet white logo
Fortinet white logo

CLI Reference

config switch-controller system

config switch-controller system

Configure system-wide switch controller settings.

config switch-controller system
    Description: Configure system-wide switch controller settings.
    set caputp-echo-interval {integer}
    set caputp-max-retransmit {integer}
    set data-sync-interval {integer}
    set dynamic-periodic-interval {integer}
    set iot-holdoff {integer}
    set iot-mac-idle {integer}
    set iot-scan-interval {integer}
    set iot-weight-threshold {integer}
    set nac-periodic-interval {integer}
    set parallel-process {integer}
    set parallel-process-override [disable|enable]
    set tunnel-mode [compatible|moderate|...]
end

config switch-controller system

Parameter

Description

Type

Size

Default

caputp-echo-interval

Echo interval for the caputp echo requests from swtp.

integer

Minimum value: 8 Maximum value: 600

30

caputp-max-retransmit

Maximum retransmission count for the caputp tunnel packets.

integer

Minimum value: 0 Maximum value: 64

5

data-sync-interval

Time interval between collection of switch data (30 - 1800 sec, default = 60, 0 = disable).

integer

Minimum value: 30 Maximum value: 1800

60

dynamic-periodic-interval

Periodic time interval to run Dynamic port policy engine (5 - 180 sec, default = 60).

integer

Minimum value: 5 Maximum value: 180

60

iot-holdoff

MAC entry's creation time. Time must be greater than this value for an entry to be created (0 - 10080 mins, default = 5 mins).

integer

Minimum value: 0 Maximum value: 10080

5

iot-mac-idle

MAC entry's idle time. MAC entry is removed after this value (0 - 10080 mins, default = 1440 mins).

integer

Minimum value: 0 Maximum value: 10080

1440

iot-scan-interval

IoT scan interval (2 - 10080 mins, default = 60 mins, 0 = disable).

integer

Minimum value: 2 Maximum value: 10080

60

iot-weight-threshold

MAC entry's confidence value. Value is re-queried when below this value (default = 1, 0 = disable).

integer

Minimum value: 0 Maximum value: 255

1

nac-periodic-interval

Periodic time interval to run NAC engine (5 - 180 sec, default = 60).

integer

Minimum value: 5 Maximum value: 180

60

parallel-process

Maximum number of parallel processes.

integer

Minimum value: 1 Maximum value: 128 **

1

parallel-process-override

Enable/disable parallel process override.

option

-

disable

Option

Description

disable

Disable maximum parallel process override.

enable

Enable maximum parallel process override.

tunnel-mode

Configure tunnel mode security (default = compatible).

option

-

compatible

Option

Description

compatible

Least restrictive. Supports the lowest levels of security but highest compatibility between all FortiSwitch and FortiGate devices. 3rd party certificates permitted.

moderate

Moderate level of security. 3rd party certificates permitted.

strict

Highest level of security requirements. If enabled, the FortiGate device follows the same security mode requirements as in FIPS/CC mode.

** Values may differ between models.

config switch-controller system

config switch-controller system

Configure system-wide switch controller settings.

config switch-controller system
    Description: Configure system-wide switch controller settings.
    set caputp-echo-interval {integer}
    set caputp-max-retransmit {integer}
    set data-sync-interval {integer}
    set dynamic-periodic-interval {integer}
    set iot-holdoff {integer}
    set iot-mac-idle {integer}
    set iot-scan-interval {integer}
    set iot-weight-threshold {integer}
    set nac-periodic-interval {integer}
    set parallel-process {integer}
    set parallel-process-override [disable|enable]
    set tunnel-mode [compatible|moderate|...]
end

config switch-controller system

Parameter

Description

Type

Size

Default

caputp-echo-interval

Echo interval for the caputp echo requests from swtp.

integer

Minimum value: 8 Maximum value: 600

30

caputp-max-retransmit

Maximum retransmission count for the caputp tunnel packets.

integer

Minimum value: 0 Maximum value: 64

5

data-sync-interval

Time interval between collection of switch data (30 - 1800 sec, default = 60, 0 = disable).

integer

Minimum value: 30 Maximum value: 1800

60

dynamic-periodic-interval

Periodic time interval to run Dynamic port policy engine (5 - 180 sec, default = 60).

integer

Minimum value: 5 Maximum value: 180

60

iot-holdoff

MAC entry's creation time. Time must be greater than this value for an entry to be created (0 - 10080 mins, default = 5 mins).

integer

Minimum value: 0 Maximum value: 10080

5

iot-mac-idle

MAC entry's idle time. MAC entry is removed after this value (0 - 10080 mins, default = 1440 mins).

integer

Minimum value: 0 Maximum value: 10080

1440

iot-scan-interval

IoT scan interval (2 - 10080 mins, default = 60 mins, 0 = disable).

integer

Minimum value: 2 Maximum value: 10080

60

iot-weight-threshold

MAC entry's confidence value. Value is re-queried when below this value (default = 1, 0 = disable).

integer

Minimum value: 0 Maximum value: 255

1

nac-periodic-interval

Periodic time interval to run NAC engine (5 - 180 sec, default = 60).

integer

Minimum value: 5 Maximum value: 180

60

parallel-process

Maximum number of parallel processes.

integer

Minimum value: 1 Maximum value: 128 **

1

parallel-process-override

Enable/disable parallel process override.

option

-

disable

Option

Description

disable

Disable maximum parallel process override.

enable

Enable maximum parallel process override.

tunnel-mode

Configure tunnel mode security (default = compatible).

option

-

compatible

Option

Description

compatible

Least restrictive. Supports the lowest levels of security but highest compatibility between all FortiSwitch and FortiGate devices. 3rd party certificates permitted.

moderate

Moderate level of security. 3rd party certificates permitted.

strict

Highest level of security requirements. If enabled, the FortiGate device follows the same security mode requirements as in FIPS/CC mode.

** Values may differ between models.