Zero-touch provisioning for FortiSwitch
Model devices used for ZTP can also be linked to model FortiAPs, enabling provisioning of AP settings when first connected.
Scenario 1: When FortiGate is provisioned as a Model Device and uses auto-link for zero-touch install
- Create a model FortiGate device by using a real FortiGate serial number.
- Configure a model device interface IP, which will be used as the management IP to FortiManager.
- In the model device, choose the interface which will be used to connect FortiSwitch, enable FortiSwitch and specify the IP address.
- In FortiSwitch Manager, create a model FortiSwitch on the FortiGate by using a real FortiSwitch serial number.
- In FortiSwitch Manager > FortiSwitch Template, create a FortiSwitch template, modify port settings and assign it to the model FortiSwitch.
- Create a policy package for the model device, then do a policy copy and perform a Copy Only to the model FortiGate.
- Connect the real FortiSwitch to the real FortiGate, and connect the FortiGate to the network that FortiManager can reach.
- Log on to FortiGate. Go to Security Fabric > Settings and configure central management to connect to FortiManager. (You can also use other method to let FortiGate learn FortiManager IP and trigger FortiManager model device auto-link function.)
- Click Apply to apply the settings and click OK to agree the grant to FortiManager.
- Go back to FortiManager and double check model device auto link function status with the real FortiGate.
- After the configuration is pushed to FortiGate, access FortiGate and verify that the FortiSwitch is enabled and displayed in FortiGate.
- Go to FortiManager > FortiSwitch Manager > Managed FortiSwitches. You can see the FortiGate status is up and FortiSwitch is now online.
Scenario 2: FortiGate is already managed by FortiManager
- Log on to FortiManager. Go to FortiSwitch Manager > Managed Switchesand click Create New. Choose FortiGate and FortiLink interface, enter the serial number, name, and click OK.
- Log on to FortiGate. Go to WiFi & Switch Controller > Managed FortiSwitch and verify that the model FortiSwitch has been deployed.
- Go to FortiManager. Go to FortiSwitch Manager > Managed Switches and verify that the model switch is also displayed.
- Assign the FortiSwitch template to the model FortiSwitch and deploy the template configuration to FortiGate.
- Connect the real FortiSwitch to the FortiGate by using FortiLink port and start the FortiSwitch. After FortiLink negotiation, the FortiSwitch is connected with FortiGate and its status is online.
- Go back to FortiManager > FortiSwitch Manager, right-click the managed FortiSwitch and click Refresh. The FortiSwitch status will displayed as Online.