New feature: FortiGate Hardware Switch Interface


Virtual switch feature enables you create virtual switches on top of the physical switch(es) with designated interfaces/ports so that a virtual switch can build up its forwarding table through learning and forward traffic accordingly. When traffic is forwarded among interfaces belonging to the same virtual switch, the traffic doesn’t need to go up to the software stack, but forwarded directly by the switch. When traffic has to be relayed to interfaces not on the virtual switch, the traffic will go through the normal data path and be offloaded to NP4 when possible.

This feature is only available on mid to high end FortiGate units, including the 100D, 600C, 1000C, and 1240B.

To enable and configure the virtual switch, enter the CLI commands:


6 Antworten auf „New feature: FortiGate Hardware Switch Interface“

  1. Hi there,

    useful to anyone searching this topic.
    The hardware switch feature is now (fortios 5.2.2 and above(?)) also available on some minor models like 60D, 90D etc.

    1. Hi Alberto,

      A redundant interface group only uses one link at a time, where an aggregate link group uses the total bandwidth of the functioning links in the group.
      You can use a redundant interfcace for example in a cluster for the heartbeat links where you don’t need link aggregation (IEEE 802.3ad).

      You can find more information here:

Schreiben Sie einen Kommentar

Ihre E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert.