Technical Tip - New Feature in FortiOS 7.4 To Authe... - Fortinet Community
Technical Tip - New Feature in FortiOS 7.4 To Authe... - Fortinet Community
asanzd Staff
Article Id 390053
Technical Tip: New feature in FortiOS 7.4 to authenticate FortiSwitch from
FortiGate
Description This article shows a new feature available since FortiOS 7.4.1 to authenticate
FortiSwitches on security fabric
Scope FortiGate, FortiSwitch.
1 de 4 07/05/2025, 18:05
Technical Tip: New feature in FortiOS 7.4 to authe... - Fortinet Community https://community.fortinet.com/t5/tkb/articleprintpage/tkb-id/TKB20/artic...
Solution FortiOS 7.4.1 has introduced a new feature to allow FortiGate to authorize the
FortiSwitch.
This guarantees that both FortiGate and FortiSwitch share the same certificate,
and that the certificate is the authentication keypoint that is validated to allow
FortiGate to authorize the switch.
Normally, only original FortiSwitches are connected to FortiGate to work in a
managed state, but this feature still provides a security layer for the authorization
process.
A restricted ISL trunk is the same as a regular ISL trunk, but FortiOS does
not add any user VLANs. The restricted ISL trunk allows limited access so
that users can authenticate unauthenticated switches. Use a restricted ISL
trunk for a new FortiSwitch unit that was just added to the Security Fabric or
a FortiSwitch unit that does not support authentication or encryption.
• Strict: If authentication succeeds, FortiOS forms a secure ISL trunk. If
authentication fails, no ISL trunk is formed.
'Strict' guarantees that a secure ISL trunk will be built only if the authentication
has completed successfully.
With the 'strict' option, the certificate to check must be configured under the lldp-
profile:
2 de 4 07/05/2025, 18:05
Technical Tip: New feature in FortiOS 7.4 to authe... - Fortinet Community https://community.fortinet.com/t5/tkb/articleprintpage/tkb-id/TKB20/artic...
108
0 Kudos
Article Feedback
3 de 4 07/05/2025, 18:05
Technical Tip: New feature in FortiOS 7.4 to authe... - Fortinet Community https://community.fortinet.com/t5/tkb/articleprintpage/tkb-id/TKB20/artic...
4 de 4 07/05/2025, 18:05