config switch-controller global
Configure FortiSwitch global settings.
config switch-controller global
Description: Configure FortiSwitch global settings.
set bounce-quarantined-link [disable|enable]
config custom-command
Description: List of custom commands to be pushed to all FortiSwitches in the VDOM.
edit <command-entry>
set command-name {string}
next
end
set default-virtual-switch-vlan {string}
set dhcp-option82-circuit-id {option1}, {option2}, ...
set dhcp-option82-format [ascii|legacy]
set dhcp-option82-remote-id {option1}, {option2}, ...
set dhcp-server-access-list [enable|disable]
set dhcp-snoop-client-db-exp {integer}
set dhcp-snoop-client-req [drop-untrusted|forward-untrusted]
set dhcp-snoop-db-per-port-learn-limit {integer}
set disable-discovery <name1>, <name2>, ...
set fips-enforce [disable|enable]
set firewall-auth-user-hold-period {integer}
set firmware-provision-on-authorization [enable|disable]
set https-image-push [enable|disable]
set log-mac-limit-violations [enable|disable]
set mac-aging-interval {integer}
set mac-event-logging [enable|disable]
set mac-retention-period {integer}
set mac-violation-timer {integer}
set quarantine-mode [by-vlan|by-redirect]
set sn-dns-resolution [enable|disable]
set switch-custom-cmd [on-replay|on-any]
set switch-on-deauth [no-op|factory-reset]
set update-user-device {option1}, {option2}, ...
set vlan-all-mode [all|defined]
set vlan-identity [description|name]
set vlan-optimization [prune|configured|...]
end
config switch-controller global
|
Parameter |
Description |
Type |
Size |
Default |
||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
bounce-quarantined-link |
Enable/disable bouncing (administratively bring the link down, up) of a switch port where a quarantined device was seen last. Helps to re-initiate the DHCP process for a device. |
option |
- |
disable |
||||||||||||
|
|
|
|||||||||||||||
|
default-virtual-switch-vlan |
Default VLAN for ports when added to the virtual-switch. |
string |
Maximum length: 15 |
|
||||||||||||
|
dhcp-option82-circuit-id |
List the parameters to be included to inform about client identification. |
option |
- |
intfname vlan mode |
||||||||||||
|
|
|
|||||||||||||||
|
dhcp-option82-format |
DHCP option-82 format string. |
option |
- |
ascii |
||||||||||||
|
|
|
|||||||||||||||
|
dhcp-option82-remote-id |
List the parameters to be included to inform about client identification. |
option |
- |
mac |
||||||||||||
|
|
|
|||||||||||||||
|
dhcp-server-access-list |
Enable/disable DHCP snooping server access list. |
option |
- |
disable |
||||||||||||
|
|
|
|||||||||||||||
|
dhcp-snoop-client-db-exp |
Expiry time for DHCP snooping server database entries (300 - 259200 sec, default = 86400 sec). |
integer |
Minimum value: 300 Maximum value: 259200 |
86400 |
||||||||||||
|
dhcp-snoop-client-req |
Client DHCP packet broadcast mode. |
option |
- |
drop-untrusted |
||||||||||||
|
|
|
|||||||||||||||
|
dhcp-snoop-db-per-port-learn-limit |
Per Interface dhcp-server entries learn limit (0 - 1024, default = 64). |
integer |
Minimum value: 0 Maximum value: 2048 |
64 |
||||||||||||
|
disable-discovery |
Prevent this FortiSwitch from discovering. FortiSwitch Serial-number. |
string |
Maximum length: 79 |
|
||||||||||||
|
fips-enforce |
Enable/disable enforcement of FIPS on managed FortiSwitch devices. |
option |
- |
enable |
||||||||||||
|
|
|
|||||||||||||||
|
firewall-auth-user-hold-period |
Time period in minutes to hold firewall authenticated MAC users (5 - 1440, default = 5, disable = 0). |
integer |
Minimum value: 5 Maximum value: 1440 |
5 |
||||||||||||
|
firmware-provision-on-authorization |
Enable/disable automatic provisioning of latest firmware on authorization. |
option |
- |
disable |
||||||||||||
|
|
|
|||||||||||||||
|
https-image-push |
Enable/disable image push to FortiSwitch using HTTPS. |
option |
- |
enable |
||||||||||||
|
|
|
|||||||||||||||
|
log-mac-limit-violations |
Enable/disable logs for Learning Limit Violations. |
option |
- |
disable |
||||||||||||
|
|
|
|||||||||||||||
|
mac-aging-interval |
Time after which an inactive MAC is aged out (10 - 1000000 sec, default = 300, 0 = disable). |
integer |
Minimum value: 10 Maximum value: 1000000 |
300 |
||||||||||||
|
mac-event-logging |
Enable/disable MAC address event logging. |
option |
- |
disable |
||||||||||||
|
|
|
|||||||||||||||
|
mac-retention-period |
Time in hours after which an inactive MAC is removed from client DB (0 = aged out based on mac-aging-interval). |
integer |
Minimum value: 0 Maximum value: 168 |
24 |
||||||||||||
|
mac-violation-timer |
Set timeout for Learning Limit Violations (0 = disabled). |
integer |
Minimum value: 0 Maximum value: 4294967295 |
0 |
||||||||||||
|
quarantine-mode |
Quarantine mode. |
option |
- |
by-vlan |
||||||||||||
|
|
|
|||||||||||||||
|
sn-dns-resolution |
Enable/disable DNS resolution of the FortiSwitch unit's IP address with switch name. |
option |
- |
enable |
||||||||||||
|
|
|
|||||||||||||||
|
switch-custom-cmd * |
Configure push method for switch bound custom command. |
option |
- |
on-replay |
||||||||||||
|
|
|
|||||||||||||||
|
switch-on-deauth |
No-operation/Factory-reset the managed FortiSwitch on deauthorization. |
option |
- |
no-op |
||||||||||||
|
|
|
|||||||||||||||
|
update-user-device |
Control which sources update the device user list. |
option |
- |
mac-cache lldp dhcp-snooping l2-db l3-db |
||||||||||||
|
|
|
|||||||||||||||
|
vlan-all-mode |
VLAN configuration mode, user-defined-vlans or all-possible-vlans. |
option |
- |
defined |
||||||||||||
|
|
|
|||||||||||||||
|
vlan-identity |
Identity of the VLAN. Commonly used for RADIUS Tunnel-Private-Group-Id. |
option |
- |
name |
||||||||||||
|
|
|
|||||||||||||||
|
vlan-optimization |
FortiLink VLAN optimization. |
option |
- |
configured |
||||||||||||
|
|
|
|||||||||||||||
* This parameter may not exist in some models.
config custom-command
|
Parameter |
Description |
Type |
Size |
Default |
|---|---|---|---|---|
|
command-entry |
List of FortiSwitch commands. |
string |
Maximum length: 35 |
|
|
command-name |
Name of custom command to push to all FortiSwitches in VDOM. |
string |
Maximum length: 35 |
|