Fortinet white logo
Fortinet white logo

CLI Reference

config switch-controller dynamic-port-policy

config switch-controller dynamic-port-policy

Configure Dynamic port policy to be applied on the managed FortiSwitch ports through DPP device.

config switch-controller dynamic-port-policy
    Description: Configure Dynamic port policy to be applied on the managed FortiSwitch ports through DPP device.
    edit <name>
        set description {string}
        set fortilink {string}
        config policy
            Description: Port policies with matching criteria and actions.
            edit <name>
                set 802-1x {string}
                set bounce-port-duration {integer}
                set bounce-port-link [disable|enable]
                set category [device|interface-tag]
                set description {string}
                set family {string}
                set host {string}
                set hw-vendor {string}
                set interface-tags <tag-name1>, <tag-name2>, ...
                set lldp-profile {string}
                set mac {string}
                set match-period {integer}
                set match-remove [default|link-down]
                set match-type [dynamic|override]
                set poe-reset [disable|enable]
                set qos-policy {string}
                set status [enable|disable]
                set type {string}
                set vlan-policy {string}
            next
        end
    next
end

config switch-controller dynamic-port-policy

Parameter

Description

Type

Size

Default

description

Description for the Dynamic port policy.

string

Maximum length: 63

fortilink

FortiLink interface for which this Dynamic port policy belongs to.

string

Maximum length: 15

name

Dynamic port policy name.

string

Maximum length: 63

config policy

Parameter

Description

Type

Size

Default

802-1x

802.1x security policy to be applied when using this policy.

string

Maximum length: 31

bounce-port-duration

Bounce duration in seconds of a switch port where this policy is applied.

integer

Minimum value: 1 Maximum value: 30

5

bounce-port-link

Enable/disable bouncing (administratively bring the link down, up) of a switch port where this policy is applied. Helps to clear and reassign VLAN from lldp-profile.

option

-

enable

Option

Description

disable

Disable bouncing (administratively bring the link down, up) of a switch port where this policy is applied.

enable

Enable bouncing (administratively bring the link down, up) of a switch port where this policy is applied.

category

Category of Dynamic port policy.

option

-

device

Option

Description

device

Device category.

interface-tag

Interface Tag category.

description

Description for the policy.

string

Maximum length: 63

family

Match policy based on family.

string

Maximum length: 31

host

Match policy based on host.

string

Maximum length: 64

hw-vendor

Match policy based on hardware vendor.

string

Maximum length: 15

interface-tags <tag-name>

Match policy based on the FortiSwitch interface object tags.

FortiSwitch port tag name.

string

Maximum length: 63

lldp-profile

LLDP profile to be applied when using this policy.

string

Maximum length: 63

mac

Match policy based on MAC address.

string

Maximum length: 17

match-period

Duration in hours to retain the matched devices (0 - 3072, 0 = always retain).

integer

Minimum value: 0 Maximum value: 3072 **

0

match-remove

Options to remove the matched override devices.

option

-

default

Option

Description

default

Remove the matched override devices based on the match period.

link-down

Remove the matched override devices based on switch port link down event.

match-type

Match and retain the devices based on the type.

option

-

dynamic

Option

Description

dynamic

Matched devices will be removed on dynamic events like link-down,device-inactivity,switch-offline.

override

Matched devices will be retained until the match-period.

name

Policy name.

string

Maximum length: 63

poe-reset

Enable/disable POE reset of a switch port where this policy is applied.

option

-

disable

Option

Description

disable

Disable POE reset of a switch port where this policy is applied.

enable

Enable POE reset of a switch port where this policy is applied.

qos-policy

QoS policy to be applied when using this policy.

string

Maximum length: 63

status

Enable/disable policy.

option

-

enable

Option

Description

enable

Enable policy.

disable

Disable policy.

type

Match policy based on type.

string

Maximum length: 15

vlan-policy

VLAN policy to be applied when using this policy.

string

Maximum length: 63

** Values may differ between models.

config switch-controller dynamic-port-policy

config switch-controller dynamic-port-policy

Configure Dynamic port policy to be applied on the managed FortiSwitch ports through DPP device.

config switch-controller dynamic-port-policy
    Description: Configure Dynamic port policy to be applied on the managed FortiSwitch ports through DPP device.
    edit <name>
        set description {string}
        set fortilink {string}
        config policy
            Description: Port policies with matching criteria and actions.
            edit <name>
                set 802-1x {string}
                set bounce-port-duration {integer}
                set bounce-port-link [disable|enable]
                set category [device|interface-tag]
                set description {string}
                set family {string}
                set host {string}
                set hw-vendor {string}
                set interface-tags <tag-name1>, <tag-name2>, ...
                set lldp-profile {string}
                set mac {string}
                set match-period {integer}
                set match-remove [default|link-down]
                set match-type [dynamic|override]
                set poe-reset [disable|enable]
                set qos-policy {string}
                set status [enable|disable]
                set type {string}
                set vlan-policy {string}
            next
        end
    next
end

config switch-controller dynamic-port-policy

Parameter

Description

Type

Size

Default

description

Description for the Dynamic port policy.

string

Maximum length: 63

fortilink

FortiLink interface for which this Dynamic port policy belongs to.

string

Maximum length: 15

name

Dynamic port policy name.

string

Maximum length: 63

config policy

Parameter

Description

Type

Size

Default

802-1x

802.1x security policy to be applied when using this policy.

string

Maximum length: 31

bounce-port-duration

Bounce duration in seconds of a switch port where this policy is applied.

integer

Minimum value: 1 Maximum value: 30

5

bounce-port-link

Enable/disable bouncing (administratively bring the link down, up) of a switch port where this policy is applied. Helps to clear and reassign VLAN from lldp-profile.

option

-

enable

Option

Description

disable

Disable bouncing (administratively bring the link down, up) of a switch port where this policy is applied.

enable

Enable bouncing (administratively bring the link down, up) of a switch port where this policy is applied.

category

Category of Dynamic port policy.

option

-

device

Option

Description

device

Device category.

interface-tag

Interface Tag category.

description

Description for the policy.

string

Maximum length: 63

family

Match policy based on family.

string

Maximum length: 31

host

Match policy based on host.

string

Maximum length: 64

hw-vendor

Match policy based on hardware vendor.

string

Maximum length: 15

interface-tags <tag-name>

Match policy based on the FortiSwitch interface object tags.

FortiSwitch port tag name.

string

Maximum length: 63

lldp-profile

LLDP profile to be applied when using this policy.

string

Maximum length: 63

mac

Match policy based on MAC address.

string

Maximum length: 17

match-period

Duration in hours to retain the matched devices (0 - 3072, 0 = always retain).

integer

Minimum value: 0 Maximum value: 3072 **

0

match-remove

Options to remove the matched override devices.

option

-

default

Option

Description

default

Remove the matched override devices based on the match period.

link-down

Remove the matched override devices based on switch port link down event.

match-type

Match and retain the devices based on the type.

option

-

dynamic

Option

Description

dynamic

Matched devices will be removed on dynamic events like link-down,device-inactivity,switch-offline.

override

Matched devices will be retained until the match-period.

name

Policy name.

string

Maximum length: 63

poe-reset

Enable/disable POE reset of a switch port where this policy is applied.

option

-

disable

Option

Description

disable

Disable POE reset of a switch port where this policy is applied.

enable

Enable POE reset of a switch port where this policy is applied.

qos-policy

QoS policy to be applied when using this policy.

string

Maximum length: 63

status

Enable/disable policy.

option

-

enable

Option

Description

enable

Enable policy.

disable

Disable policy.

type

Match policy based on type.

string

Maximum length: 15

vlan-policy

VLAN policy to be applied when using this policy.

string

Maximum length: 63

** Values may differ between models.