Fortinet white logo
Fortinet white logo

CLI Reference

config switch-controller fortilink-settings

config switch-controller fortilink-settings

Configure integrated FortiLink settings for FortiSwitch.

config switch-controller fortilink-settings
    Description: Configure integrated FortiLink settings for FortiSwitch.
    edit <name>
        set access-vlan-mode [legacy|fail-open|...]
        set admin-policy {string}
        set fortilink {string}
        set inactive-timer {integer}
        set link-down-flush [disable|enable]
        config nac-ports
            Description: NAC specific configuration.
            set lan-segment [enabled|disabled]
            set member-change {integer}
            set nac-lan-interface {string}
            set nac-segment-vlans <vlan-name1>, <vlan-name2>, ...
            set onboarding-vlan {string}
            set parent-key {string}
        end
    next
end

config switch-controller fortilink-settings

Parameter

Description

Type

Size

Default

access-vlan-mode

Intra VLAN traffic behavior with loss of connection to the FortiGate.

option

-

legacy

Option

Description

legacy

Backward compatible behavior.

fail-open

When connection to FortiGate is lost, traffic on the VLAN may continue directly between end points.

fail-close

When connection to FortiGate is lost, traffic between endpoints on the VLAN is blocked.

admin-policy *

FortiSwitch's admin security-policy applied to all switch on this Fortilink interface.

string

Maximum length: 31

fortilink

FortiLink interface to which this fortilink-setting belongs.

string

Maximum length: 15

inactive-timer

Time interval(minutes) to be included in the inactive devices expiry calculation (mac age-out + inactive-time + periodic scan interval).

integer

Minimum value: 1 Maximum value: 1440

15

link-down-flush

Clear NAC and dynamic devices on switch ports on link down event.

option

-

enable

Option

Description

disable

Disable clearing NAC and dynamic devices on a switch port when link down event happens.

enable

Enable clearing NAC and dynamic devices on a switch port when link down event happens.

name

FortiLink settings name.

string

Maximum length: 35

* This parameter may not exist in some models.

config nac-ports

Parameter

Description

Type

Size

Default

lan-segment

Enable/disable LAN segment feature on the FortiLink interface.

option

-

disabled

Option

Description

enabled

Enable lan-segment on this interface.

disabled

Disable lan-segment on this interface.

member-change

Member change flag. Read-only.

integer

Minimum value: 0 Maximum value: 255

0

nac-lan-interface

Configure NAC LAN interface.

string

Maximum length: 15

nac-segment-vlans <vlan-name>

Configure NAC segment VLANs.

VLAN interface name.

string

Maximum length: 79

onboarding-vlan

Default NAC Onboarding VLAN when NAC devices are discovered.

string

Maximum length: 15

parent-key

Parent key name. Read-only.

string

Maximum length: 35

config switch-controller fortilink-settings

config switch-controller fortilink-settings

Configure integrated FortiLink settings for FortiSwitch.

config switch-controller fortilink-settings
    Description: Configure integrated FortiLink settings for FortiSwitch.
    edit <name>
        set access-vlan-mode [legacy|fail-open|...]
        set admin-policy {string}
        set fortilink {string}
        set inactive-timer {integer}
        set link-down-flush [disable|enable]
        config nac-ports
            Description: NAC specific configuration.
            set lan-segment [enabled|disabled]
            set member-change {integer}
            set nac-lan-interface {string}
            set nac-segment-vlans <vlan-name1>, <vlan-name2>, ...
            set onboarding-vlan {string}
            set parent-key {string}
        end
    next
end

config switch-controller fortilink-settings

Parameter

Description

Type

Size

Default

access-vlan-mode

Intra VLAN traffic behavior with loss of connection to the FortiGate.

option

-

legacy

Option

Description

legacy

Backward compatible behavior.

fail-open

When connection to FortiGate is lost, traffic on the VLAN may continue directly between end points.

fail-close

When connection to FortiGate is lost, traffic between endpoints on the VLAN is blocked.

admin-policy *

FortiSwitch's admin security-policy applied to all switch on this Fortilink interface.

string

Maximum length: 31

fortilink

FortiLink interface to which this fortilink-setting belongs.

string

Maximum length: 15

inactive-timer

Time interval(minutes) to be included in the inactive devices expiry calculation (mac age-out + inactive-time + periodic scan interval).

integer

Minimum value: 1 Maximum value: 1440

15

link-down-flush

Clear NAC and dynamic devices on switch ports on link down event.

option

-

enable

Option

Description

disable

Disable clearing NAC and dynamic devices on a switch port when link down event happens.

enable

Enable clearing NAC and dynamic devices on a switch port when link down event happens.

name

FortiLink settings name.

string

Maximum length: 35

* This parameter may not exist in some models.

config nac-ports

Parameter

Description

Type

Size

Default

lan-segment

Enable/disable LAN segment feature on the FortiLink interface.

option

-

disabled

Option

Description

enabled

Enable lan-segment on this interface.

disabled

Disable lan-segment on this interface.

member-change

Member change flag. Read-only.

integer

Minimum value: 0 Maximum value: 255

0

nac-lan-interface

Configure NAC LAN interface.

string

Maximum length: 15

nac-segment-vlans <vlan-name>

Configure NAC segment VLANs.

VLAN interface name.

string

Maximum length: 79

onboarding-vlan

Default NAC Onboarding VLAN when NAC devices are discovered.

string

Maximum length: 15

parent-key

Parent key name. Read-only.

string

Maximum length: 35