Overview
Join Keith Barker as he discusses and demonstrates FortiSwitch topologies and Spanning Tree Protocol (STP).
Recommended Experience
- An understanding of concepts taught in CompTIA Network+ (N10-007), CompTIA Security+ (SY0-601), and Fortinet NSE 4 - FortiOS is recommended.
Related Certifications
- Fortinet NSE 6 - FortiSwitch
Related Job Functions
- Security administrator
- Security engineer
- Network security professional
Keith Barker has been a CBT Nuggets trainer since 2012 and has earned a variety of certifications, including Cisco CCIE Routing and Switching, Cisco CCIE Security, Cisco CCDP, HP-MASE, Brocade BCNP, (ISC)2 CISSP, CompTIA’s Network+ and Security+, VMware VCP5-DCV, Palo Alto CNSE, Check Point CCSA.
Intro to FortiSwitch Topologies and STP
Keith introduces this set of videos.
Topologies and STP Overview
Keith presents an overview of L2 topology options and the function of Spanning Tree Protocol (STP).
Knowledge Check
Which links use 802.1Q tagging to identify the VLAN that a frame belongs to? (Choose three)
Single FGT to Single FSW
Keith demonstrates a layer 2 topology with a single FortiGate (FGT) connecting to a single FortiSwitch (FSW) over the FortiLink interface.
Knowledge Check
Which of the following is how one verifies that the FortiOS firmware on the FortiGate is compatible with the FortiSwitchOS firmware on the FortiSwitch?
Single FGT to FSW Stack
Keith demonstrates a FortiGate managing a FortiSwitch stack.
Knowledge Check
How many FortiGate FortiLink interfaces are required to manage a stack of 3 FortiSwitches?
HA FortiGates and FortiSwitch
Keith demonstrates how to use an HA FortiGate pair to manage a FortiSwitch stack.
Knowledge Check
In this FortiGate HA topology shown in the video, if SW1 fails, there is still fault tolerance for SW2 and SW3. True or false?
Spanning Tree Protocol
Keith presents an overview of the purpose and methods used by Spanning Tree to prevent layer 2 loops.
Knowledge Check
Which devices in spanning tree will have decided upon and selected a root port?
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Intro to FortiSwitch Topologies and STP
0:07Hello and welcome.
0:09My name is Keith Barker.
0:10And in this set of videos, you and I
0:12are going to focus our attention on two basic things.
0:14Number one, the options we have regarding topologies
0:17in a layer 2 switching environment with FortiSwitch.
0:19And secondly, how do we-- if we have parallel paths,
0:22how do we prevent broadcast storms and loops
0:24from occurring?
0:25And that's with a feature called Spanning Tree.
0:26So in the next video, we'll take a big-picture look
0:28at some of those concepts.
0:30Then I'll walk you through step-by-step several
0:32of our options with both.
0:33So I'll see you, my friend, in the very next video.
Topologies and STP Overview
0:00[MUSIC PLAYING]
0:06And welcome back.
0:07Using a FortiGate and its FortiLink interface
0:10to control one or more switches is a pretty amazing idea.
0:12And in this video, I'd like talk with you
0:14about some of our options regarding the connections
0:16and interconnections of switches and the FortiGate
0:18as well as a high-level overview regarding Spanning Tree
0:21Protocol.
0:22So let's start off with a single FortiGate and a single switch.
0:25And for that connection, we're going to use the FortiLink
0:28interface on the FortiGate.
0:29And then from the FortiSwitch, effectively, it's
0:31a trunk going up to the FortiGate.
0:33And trunks are going to use 802.1Q tagging.
0:36So if there's a frame for VLAN 10,
0:37it can be tagged on that trunk and sent up.
0:39And that way, the receiving device can know,
0:41oh, this is for VLAN 10, or oh, this is for VLAN 20.
0:44So I'd like you to remember that whenever we're talking about
0:46the FortiLink interface coming from the FortiGate
0:48and the FortiLink trunk coming up from the switch that
0:50it's supporting 802.1Q that's being used to tag and identify
0:54the individual frames as they go back and forth between those
0:56devices.
0:57So that's one option for a topology, one FortiGate
1:00and one FortiSwitch.
1:01And this link here could be a link aggregation group,
1:03or it could be a single interface.
1:05Either way is great.
1:06In fact, let me just assume we want some fault tolerance.
1:08And so I'll go ahead and put another one there
1:10and represent that as a link aggregation group right there.
1:13Now, another option we have is a FortiGate.
1:15So I'll draw that in.
1:16And instead of having one switch,
1:18we could have a stack of switches.
1:19Let me just go ahead and put three there.
1:21And once again, the connection between the FortiGate
1:23and the switch stack is going to be through FortiLink.
1:26And so if we're just going to one switch here,
1:28once again, that would be a link aggregation group.
1:30And then, we would have interconnections
1:32between these switches.
1:33And these connections between these switches
1:35are called ISLs, or Inter-Switch Links.
1:37Now, it's a little bit unfortunate,
1:40because that acronym also represents--
1:43in the world of Cisco Systems, it
1:44represents their proprietary trunking protocol
1:47they came out with like 20 years ago,
1:48but they don't use it anymore.
1:50The industry is now using 802.1Q.
1:53So on this FortiLink connection from the FortiGate
1:55and the FortiLink trunk coming from the switch,
1:58it's also using 802.1Q for tagging.
2:00And these Inter-Switch Links are also using 802.1Q tagging.
2:04And once again, the acronym of ISL
2:06should not be confused with the Cisco old technology that was
2:09used for trunking previously.
2:10It's just the logical name for that connection between
2:13the switches that's supporting 802.1Q.
2:16So let's take a look at yet another option.
2:17We have another option, which would involve
2:19high availability, an HA pair.
2:21So here is FGT--
2:23I'll put P for primary, and we'll
2:25have the FGTS for secondary.
2:28They've got their HA connection between them.
2:30And if they're connecting to one switch,
2:32we'll get a connection here and a connection here.
2:34And if we're running active standby,
2:36the firewall that's active would be actually interacting
2:38with the switch and support the FortiLink interface.
2:41And this same scenario could hold true
2:42if we had a switch stack right here as well.
2:45So FSW1, FSW2, FSW3.
2:49And still on the idea of HA, we have yet another option.
2:52So I'll put primary and secondary there
2:54for the firewalls.
2:55And let's put in some switches here,
2:57except I'll put these side by side.
2:59And of course, they've got their HA connection between them.
3:01And then, for the FortiLink interface,
3:03the primary would be connected to both stacks,
3:05and the secondary would be connected to both stacks,
3:08except the connection from the secondary
3:09wouldn't be used unless that secondary firewall went active.
3:12So on this HA pair here, I'll do the same treatment
3:14with the dotted line representing that's a backup.
3:17Also for fault tolerance, we could have ISLs here,
3:19Inter-Switch Links, also using 802.1Q for fault tolerance.
3:23Another option is deal with HA.
3:25I'll put it over here, do my two firewalls.
3:27And for the switch, we could have a two-tier hierarchy.
3:30So the FortiGates could go ahead and have their FortiLinks going
3:33down to this primary device, coming
3:35down here to this switch.
3:36And I'll label this FortiSwitch one.
3:38And then, below that, we could have additional FortiSwitches.
3:40Now, let's go ahead and put three and four there
3:43and then Inter-Switch Links between those.
3:45So this is referred to as a two-tier topology
3:47with this initial FortiSwitch one
3:49being the tier one and then the two below it being in tier two.
3:52And while I'm thinking of it, let
3:53me add another option over here with another FortiGate that's
3:56working with a stack of switches,
3:58so if they've got their ISL, their Inter-Switch Links.
4:00And what we could do with a FortiLink
4:02is we could have one of the members of the FortiLink
4:04go to the first switch and the second member of the FortiLink
4:07go to this third switch.
4:09Now, in this scenario, if we're not
4:11using multi-chassis link aggregation, which we'll
4:14talk about here in just a moment,
4:15on the FortiLink interface, we need
4:16to enable the split interface for FortiLink
4:20up at the FortiGate.
4:21So by enabling this split interface,
4:23the FortiGate is only going to have one of its two members
4:25here active at a time.
4:27So it might be the one going to FortiSwitch one,
4:29or maybe it'll be the one that's going to switch three.
4:31But it won't be both at the same time.
4:33So one, think of it like the primary path.
4:35And if that fails, it can then enable the secondary path,
4:38but it won't use it simultaneously.
4:39So in this corner right here, let
4:41me go ahead and label this as multi-chassis link aggregation.
4:45And this can be done with a single FortiGate
4:46or multiple FortiGates.
4:48So here at the top, we have our FortiGate.
4:50And then, here, we're going to have two switches that
4:52are acting as MC LAG peers.
4:53And then, between those two devices,
4:55we're going to have a connection,
4:56but it's not just an ISL.
4:57It's called an ICL, an Inter-Chassis Link,
5:02which is providing connectivity directly between FortiSwitch
5:04one and FortiSwitch two.
5:06So if we're going to use MC LAG, we
5:07have to have the FortiSwitches that support MC LAG.
5:10And for the FortiLink interfaces,
5:12we're going to go like this, from the FortiGate
5:14to FortiSwitch one and from the FortiGate to FortiSwitch two.
5:17And this is all one lag.
5:20And at this point, with multi-chassis link aggregation,
5:23we can disable the split interface for FortiLink.
5:27And that, we can leverage in this example, all four
5:29members of the FortiLink.
5:31So here, I'll jot down disable FortiLink split interface.
5:35And with multi-chassis link aggregation,
5:37we could do that also in combination
5:39with high availability as well.
5:41So with these options in mind, let's turn our attention
5:43to what happens if we have parallel paths between two
5:47or more switches?
5:48So let's imagine we have a switch here,
5:50and a switch here, and a switch here, and another one here.
5:54And we'll have a FortiGate with this FortiLink connected
5:57to one of those.
5:58Let's go ahead and do it right here
5:59with a link aggregation group.
6:00And then, for the ISLs, let's go ahead
6:02and do this, and this, and this.
6:05And let's imagine for this discussion
6:06we're just going to talk about one specific VLAN.
6:08So let's imagine we have a port here
6:10where the native VLAN in the world of FortiSwitch
6:12is VLAN one, and we have a device
6:14that's connected on this port.
6:15So there's our connection.
6:17And maybe this device is a PC or some other networking device.
6:21So logically, this PC that's connected to this port
6:24belongs to VLAN number one.
6:25So in the world of IP, there's a lot of broadcast that happen.
6:28For example, this client does an ARP request,
6:30address resolution protocol.
6:32It sends out a layer two broadcast
6:34that needs to be forwarded to all of the devices that
6:37are in VLAN one.
6:38In fact, let me change this scenario a little bit.
6:39Let's go ahead and make this VLAN 10 just for clarity.
6:42So now, this PC is in a port that
6:44has been assigned as VLAN 10.
6:46If this client does an ARP request,
6:48that broadcast needs to go to all of their ports associated
6:51with VLAN 10.
6:52So switch three is going to forward it over this trunk,
6:54the Inter-Switch Link, tagging it with VLAN 10 using 802.1Q
6:58tagging.
6:59Switch one is going to receive it, forward
7:01it to any other ports that it may
7:02have that are associated with VLAN 10 that are active and up.
7:05So that broadcast is going to go here,
7:07and here, and here, and here, assuming those ports are up.
7:09And switch three also has a trunk that goes down
7:11to switch four, another ISL.
7:12So the broadcast would be forwarded that way.
7:14And if there's any ports associated with VLAN 10
7:17on FortiSwitch four, it'd be forwarded up those ports,
7:19again, if those ports are up and active.
7:21And FortiSwitch four has an ISL, which is using 802.1Q tagging.
7:25So it would forward it with the appropriate VLAN 10
7:27tag over to FortiSwitch two, who would also
7:29forward it out any ports that are associated with VLAN 10.
7:33So no problem whatsoever so far.
7:36However, what if we did this?
7:38What if we added another ISL Inter-Switch Link right here,
7:42between FortiSwitch one and FortiSwitch two?
7:45Here's the problem.
7:45That ARP request, the broadcast that comes in,
7:48could go like this and just keep on going.
7:50That's because at layer two, there
7:52is no time to live feature, such as in an IP layer three packet.
7:56At layer two, there's no such time to live mechanism.
7:59So a frame could just be forwarded over, and over,
8:01and over again, and not just clockwise
8:03but also counterclockwise.
8:05And that causes all kinds of problems
8:06to show up in the network.
8:07Besides chewing up tons of bandwidth,
8:09the source Mac address is showing up
8:11on all these different ports, and the Mac tables
8:13are flapping.
8:14And it's a big problem.
8:15So the question may be, well, how do we solve that problem?
8:18And the answer is, we're going to solve that
8:20with a protocol called Spanning Tree Protocol, this guy
8:23right here.
8:23And there are several flavors of it.
8:25There is the original flavor, which has a standard number
8:28of 802.1D as in David.
8:30And then, there were some improvements on it,
8:32which is 802.1W for Rapid Spanning Tree and yet another
8:36one called 802.1S that was the original terminology for that
8:40flavor, which is referred to as multiple spanning tree.
8:43And here's the big picture overview regarding
8:45what Spanning Tree does.
8:46Spanning Tree has a method by using BPDUs, bridge protocol
8:49data units, to basically send out little messages
8:52and identify when there is a layer two
8:54loop or parallel paths in the network.
8:56And through a very logical process it follows,
8:59it's able to go ahead and prevent a loop.
9:01So if it sees this type of a loop,
9:03it can go ahead and tell one of these interfaces
9:06to stop forwarding.
9:07And that would prevent the loop from happening.
9:09So as far as which ports are going to forward
9:11and who's going to block based on the Spanning Tree, that's
9:14a discussion we're going to have in this set of videos
9:16in greater detail.
9:17But I wanted to point out in this overview
9:18that it's Spanning Tree Protocol that's
9:20doing the work behind the scenes to identify
9:23a parallel path at layer two and then proactively blocking
9:26on that path, so we don't have layer two loops.
9:29So now that we've taken a big picture
9:31look at some of our topology options with FortiSwitch
9:33and also a high-level concept of the Spanning Tree, let's
9:36continue this journey in the next video
9:37as we begin to walk through some of our topology options.
9:40So I'll see you in the next video in just a moment.
9:42Meanwhile, I hope this has been informative,
9:44and I'd like to thank you for viewing.
Single FGT to Single FSW
0:00[MUSIC PLAYING]
0:06And welcome back.
0:08Out of all the different typologies
0:09we talked about in the overview, our first option
0:11we looked at was one FortiGate.
0:13That can then go ahead and manage one FortiSwitch using
0:16the FortiLink interface, and that's the first one
0:18we're going to demo together.
0:19So let's map this out and then, oh, that's big.
0:22So let's map this out.
0:23I've got our firewall one, which will be our FortiGate,
0:25and we've got a switch, and we'll go ahead and use a 108E.
0:29So the FortiGate is a 60F, and the switch
0:32is a 108E and then for the FortiLink,
0:35let's use ports A and B, which are already
0:37part of the default FortiLink interface on this firewall.
0:40And let's plug that into port seven and eight,
0:43and in a previous set of videos, we already
0:45identified that port seven and eight already
0:47set up for FortiLink auto-discovery,
0:49so that shouldn't be a problem.
0:50But one other thing we also want to be aware of
0:52is compatibility regarding the FortiOS that's
0:55running on the firewall and the FortiSwitchOS, which
0:58is running on the FortiSwitch.
1:00So let's pause for a moment and take a peek
1:02at the compatibility matrix, and I just
1:04did a Google search for it.
1:06Let me make it a little bit bigger here.
1:07So we're getting FortiLink compatibility,
1:09it's got the FortiOS on the left, and across the top,
1:12it has the FortiSwitchOS flavors and versions.
1:15And the R is the recommended, so they're
1:17recommending that if you have FortiOS 7.0.5, that they're
1:21recommending you use FortiSwitchOS 7.0.3,
1:24and as new flavors and versions come out,
1:26they're going to update this matrix as well.
1:28But I also want to point out that if we
1:30go down here to the very tail end over here to the 3.6.11.
1:34So one of the questions that might come up
1:36is why in the world is there an R
1:37there, for recommended for 3.6.11, as well as 7.0.3
1:42if we're using the FortiOS's 7.0.5?
1:45And the answer is we may have a switch [LAUGHING] that
1:48doesn't support version six or version seven,
1:50and that's why it's recommended.
1:52So oftentimes, companies will want
1:53to use the latest and greatest version that
1:55is supported on their hardware, as long as it's compatible.
1:58So what this is saying is that if we
2:00have an older switch with FortiSwitchOS 3.6.11
2:03and we have FortiOS on the firewall with 7.0.5,
2:07that those are not only compatible but recommended.
2:10So if we're running an older version like 3.6.4
2:12or something like that, we'd want to upgrade that for switch
2:15to 3.6.11 for compatibility and functional purposes.
2:19So here in my lab environment, the 108E that I'm using
2:22is running, I think 703 or maybe even 704,
2:25and the FortiOS on the firewall is running 705.
2:28So I think we're going to be super compatible there.
2:30So go ahead minimize that, bring back my graphic,
2:33and I think we're good to go.
2:34So before we actually bring up this FortiSwitch,
2:36I also want to take a peek at my FortiLink interface just
2:39to verify that physical interfaces A
2:41and B are both members.
2:42Also, because I'm going to the same switch,
2:44I don't have to enable the split interface.
2:46I can use both interfaces as a link aggregation
2:49group for effectively two gigabits of throughput
2:52between firewall one and the FortiSwitch.
2:54So let's go take a look at the firewall first.
2:56So here we go, so this is the firewall
2:59showing 7.0.5, that looks good.
3:01And right here, under the Security fabric,
3:03it doesn't show any FortiSwitch is connected.
3:05Also, here on firewall one, if we go down to Network
3:08and we click on Interfaces, this is
3:09just one way of looking at the FortiLink interface.
3:11We can double click on it right here, so this is showing us
3:14we have these two members, A and B,
3:15and automatically authorize devices
3:17is enabled from a previous set of videos.
3:19And FortiLink split interface is disabled, that means
3:22it won't just use one of those two member interfaces.
3:24It'll go and use both, because we're connecting
3:26to the same exact switch.
3:28So here's the IP address that we have on that logical interface
3:30here on the firewall, and here is the DHCP range
3:33that we're going to hand out from when FortiSwitches
3:36connect.
3:36All right, that looks good, and just to confirm,
3:38we don't have anybody here.
3:40Let's go down to Wi-Fi and Switch Controller,
3:42click on the link for Managed FortiSwitches
3:44right here, and sure enough, nobody's here.
3:46So I'm going to walk back to the rack
3:48and plug those cables in, and just for grins,
3:50I'm going to take another peek there.
3:51So port A on the firewall goes to port seven on the switch,
3:54and part B goes to port eight, fantastic.
3:57All right, those connections are made.
3:58I also took a little pen and hit the Mode button,
4:01and held it down for at least 10 seconds
4:03to reset the switch to factory defaults.
4:05So in just a few moments, they should
4:06power up and be auto-discovered by the FortiGate.
4:09So let's see if that's happening, we'll go ahead
4:11and go to Manage FortiSwitches.
4:13Sure enough, right there, it is coming online.
4:16We could also go to the CLI, and at the CLI on the FortiGate,
4:19we could do an execute switch-controller
4:22get-conn-status and then press Enter,
4:24and that will also show us.
4:26So currently, there it is, there's a switch ID,
4:28and any configuration it had in standalone mode
4:31is going to be wiped out.
4:33So currently, it says it's authorized,
4:34and that's because the FortiLink interface was set up
4:37for automatic authorization, but it's showing as down.
4:40There's no IP address assigned yet,
4:41so it's very likely in the process of rebooting right now.
4:45So we'll hit the up arrow key here,
4:46and looks like we need to get that a few moments.
4:48And while it's coming up, what we can do
4:51is we can right-click here, and just edit it,
4:53and we can give it a name.
4:54Let's call that guy Switch One, and we'll click on OK also,
4:58while we wait, we can just click on the FortiLink interface
5:00right here.
5:01You just verify that A and B are both green,
5:03and that's because we're not doing split interface,
5:05and we have both those connections
5:06going to the switch.
5:07And at this moment, this link on both of those ports,
5:09and that's why they're both showing green,
5:10so that's a good sign.
5:11If you go back to Manage switches again, ah, look,
5:14he's online.
5:14Good.
5:15Good.
5:15Good.
5:16So there's this name that we just gave it.
5:17There's the serial number, that's the model,
5:20there's our firmware version, fantastic.
5:22If we scroll to the right, there's the IP address
5:24that it was assigned via DHCP, via the FortiLink interface,
5:27and has been up for just a few minutes.
5:29All right, so if we click here on List and from the dropdown
5:32click on Topology, this should show us the topology.
5:36Look at that.
5:36Let me click on Refresh here.
5:38Nope.
5:38Nope.
5:38Nope.
5:39I know it's there because we saw the switch,
5:41so I'm going to go back to List.
5:42So it's here, if we go back to Topology it has not shown up.
5:46Sometimes this takes a few minutes to show up and update,
5:49so if you change your physical connections, your ISLs,
5:51and so forth, sometimes it does take a few minutes to show up.
5:54I do want to wait just for a moment or two just
5:56to make sure it shows up, and that'll
5:57give us an opportunity to verify the links involved
6:00between the firewall.
6:01Firewall one and the FortiSwitch,
6:03all right, one more refresh did it for us, fantastic.
6:05So if we hover on this link right here,
6:08it'll give us the details about all the ports involved.
6:10So port A, [LAUGHING] I'm laughing
6:15because it hasn't quite settled yet because it's
6:18showing interface A twice.
6:20It should be A and B going to port seven and eight
6:22because that's literally how it's connected.
6:24So I'm going to give this a few more moments to settle.
6:26So I'm going to do a refresh one more time, hover over that link
6:30again.
6:31So it's been a moment still showing port A twice.
6:33Now literally, it's port A and port
6:35B, so here on the firewall, if we hover here,
6:38it's showing the members as port A and port B,
6:40and as far as the physical connections involved,
6:43that should reflect A and B as well.
6:45All right, not a showstopper.
6:46So from here with this switch, if we wanted to go to the CLI
6:49on the switch, there are several ways of doing it.
6:50We could right-click on the switch and from the dropdown,
6:53say, I want to connect to the CLI,
6:54and that gives us a command-line interface over to that switch.
6:57So it's forcing me to change the password from nothing
6:59to something.
7:00So now here is the CLI for that switch.
7:02Go ahead and close that, and if you go back to our List View,
7:05there's a list of all our switches.
7:07At this moment, it's just one, and once again, we
7:10have options for Edit and Diagnostics and Tools,
7:12which we peeked out in a previous set of videos.
7:14But we'll click on it again here,
7:15so here's the details on that switch,
7:17including CPU and Memory Usage and Uptime.
7:20Here's the Faceplate with the ports that are currently up.
7:22There's details on the ports down here
7:24we can scroll through.
7:25There's the Cable Test option, a section for logs,
7:28and CLI access again, right here.
7:30And if we want to see logging information from the switch,
7:33if we go down to Log and Report and we click on Events,
7:36there's a section right here for FortiSwitch Events.
7:38So if we click here on FortiSwitch Events,
7:40currently is pulling from FortiGate Cloud,
7:42but we could also look at Memory,
7:44and here's the work that we did over the last 10 minutes.
7:46Everything before that was me playing around and verifying.
7:49So the switch was Discovered, it was automatically
7:51Authorized based on the FortiLink interface,
7:54it built a CAPWAP Tunnel.
7:55So when we do logging from these switches over to the FortiGate,
7:59it's logically done over the CAPWAP tunnel.
8:01And if we want to take a look at the details for this,
8:03we can click on the Details button
8:04to get more details on what that event was all about.
8:06All right, so going back to Wi-Fi and Switch Controller
8:09and our managed for FortiSwitches,
8:10and once again, we'll go back to our Topology view.
8:13So this is an example of one FortiGate with its FortiLink
8:16interface and aggregate interface connecting
8:18to a single switch, which in our case is switch one.
8:21And in the next video, we're going
8:22to build our switching environment
8:24by creating a switching stack by attaching a second switch
8:27behind switch number one.
8:29So that's what we get to do in the next video.
8:31I'll see you there in just a moment.
8:32Meanwhile, I hope this has been informative,
8:34and I'd like to thank you for viewing.
Single FGT to FSW Stack
0:00[MUSIC PLAYING]
0:06And welcome back.
0:07In the previous video, we had a single FortiGate
0:09with its FortiLink interface managing now one FortiSwitch.
0:13In this video, we're going to add on to that
0:15by creating a stack of switches by adding at least one,
0:18maybe two additional switches to our existing environment.
0:21So here's what I propose we do, let's go ahead
0:23in creating our stack.
0:24We already have our FortiGate, we already
0:25have our initial switch with the FortiLink connection
0:28and the FortiLink trunk between the firewall and that switch.
0:31Let's go ahead and add a couple of additional switches
0:34side by side.
0:34We'll make a second tier.
0:36So let's create switch 3 and switch 4.
0:38And all we need to do on these switches
0:40is make sure that the porch we're using on these switches
0:43are enabled for auto discovery.
0:45If they are, they'll be automatically discovered
0:47by the firewall.
0:48So on this switch, which is a 180e, it has two SFP ports,
0:53small form pluggable formats.
0:55And I have a couple of adapters that are plugged in there.
0:58I bought a bag of them about, I don't know, a year or two ago,
1:01just miscellaneous ones.
1:02And so assuming they work, if we want to use those,
1:05those are ports 9 and 10, and what I propose we do
1:09is let's take port 9 with some fiber optic cable
1:11and go from the SFP in port number 9
1:14over to the SFP on switch 3 also in port number 9.
1:18And let's take the SFP in port number 10
1:21and use some fiber optic cable to go ahead and connect over
1:23here to the SFP on switch 4 on its port number 10.
1:27They don't use the same numbers.
1:28But I want to do that just so I know which switch
1:30is connected to which port.
1:31Now, these two switches here, they
1:33are 108D power over Ethernet, 108D.
1:38And I bought these used.
1:39So this one right here is fairly current
1:41running what was the 703 or 704 of the software.
1:45And these two, I think they're running 3.6.11.
1:50So based on the matrix that we looked at, the compatibility
1:53matrix, they should still work because they're
1:55running that version of software, which the matrix said
1:58was compatible with the 40 OS, which was 7.05.
2:02So there's a few variables here but we'll check it out
2:04together.
2:05So also here on switch 1, I'm going
2:06to go ahead and click on it, and click here
2:08on diagnostics and tools.
2:09And so here on the faceplate shows ports 9 and 10
2:12are the SFPs and look at that.
2:14I'm just hovering on the faceplate over port 9.
2:17It says this transceiver is not certified by Fortinet
2:20and it's a Cisco agilent.
2:22And what do I have in port 10?
2:24A Cisco-- wow, I've got two different SFPs
2:28and they're both not supported by Fortinet.
2:30But in my testing, they worked.
2:32So I'm going to go ahead and use them.
2:33So based on our plan, we'll have port 9 on this initial switch
2:36go to switch 2 and port 10 go to switch number 3.
2:40I'll go make those physical connections right now.
2:42And I thought, let me just show you the cables real quick
2:45before I plug them in.
2:46And so the SFPs have the LC connector for the fiber
2:48and that's what these are here.
2:50So I'm going to use this one between switch 1 and switch 2,
2:53and this one between switch 1 and switch 3.
2:56All right, so those are plugged in.
2:57And I also took the liberty of resetting switch 2 and switch 3
3:02to their factory defaults.
3:03I did that by just pushing a pan on the mode button for at least
3:0610 seconds, and that resets them to their default
3:08and reboots them.
3:09So let's go ahead and close this.
3:11And OK, good, good, we're having some indicators
3:13here on the topology view.
3:15So with managed FortiSwitches is selected,
3:17let's go back to our list.
3:19So currently, I don't see additional switches.
3:21But if we go to the CLI, that's probably a faster way
3:23to see the activity.
3:24So we'll do an execute, switch controller, get
3:27connection status, and enter.
3:30Oh, there we go, yes, the other ones coming up.
3:32So there's the 108D, one of them.
3:34And in just a few minutes, we should see the second one
3:37as well.
3:38So I'm going to give that about 4 or 5 minutes to settle,
3:40and then, we'll come back and take a look at the results.
3:42All right, so it's been about a minute,
3:43still in the process of onboarding.
3:45So let's go back to our list here
3:47and go to the topology view.
3:49So in a few moments, this topology view
3:50is going to show us the connection.
3:52So whoever is connected to port 9, that's
3:54switch 2 and whoever is connected
3:55to port 10, that's switch 3.
3:57So I'm going to wait just a moment
3:59before I try to rename these, so I can put the right name
4:01on the right switch.
4:02All right, so it's been a moment and it just refreshed.
4:05And this is port number 9, so that is switch number 2.
4:07So I'm going to rename that by right clicking.
4:10Click on edit and we'll call that switch 2.
4:12Fantastic, and click on OK.
4:15And then, this must be switch 3.
4:16It'll show up here in a moment being connected to port 10.
4:19So we'll edit and we'll call this guy switch 3.
4:21So it looks like switch 3 is up.
4:23So if we want to go to the CLI on that switch for any reason,
4:25we could right click on it.
4:26And then, from the dropdown, click on right here,
4:28connect to CLI, command line interface.
4:30All right, we are connected.
4:32So do a get system status on that device.
4:35It's a FortiSwitch 108D version 3.6.11.
4:39There's the serial number, the BIOS version,
4:41the burned in Layer 2 address, the Mac address, the host name
4:44we gave it, fantastic.
4:46And let's do a config switch trunk.
4:48Let's do a quick show command.
4:49So this is showing us that this port, which is port number 10,
4:53is a trunk as due to auto ISL, the interswitch link
4:56between switch 1 and switch 3.
4:58And it's using link access control protocol
5:01to negotiate that trunk.
5:03So when we have two devices like these two switches here,
5:06switch 1 and switch 3, and they've got their ISL
5:09connection between them, which is the labeling for the trunk
5:13that set up between them, and that trunk is using 802.1Q.
5:16And negotiating and setting up that trunk,
5:19they used link aggregation control protocol,
5:21which is an open standard.
5:22And the option is for link aggregation control Protocol
5:25are active or passive.
5:27And so if this site is active and this site is active,
5:30that means they will both initiate
5:31a conversation with the other side to negotiate a trunk.
5:34If one site is active and the other site is passive,
5:36the active site will start the conversation
5:39and they'll set up a trunk.
5:40So active-active works on either side, active-passive works.
5:43However, what doesn't work is passive on one side
5:46and passive on the other side.
5:47It's like two people just waiting for the other one
5:49to make a move and nobody starts the conversation.
5:52Now, the cool thing about this is that with auto ISL,
5:55we had to do nothing about that, it just automatically did it
5:59by itself as part of FortiSwitch.
6:01Also, behind the scenes, you're using LLDP, link layer
6:05discovery protocol to identify who
6:07the peer is and the details of that peer who's
6:09connected over that link.
6:11And we don't have to go to the CLI on the actual switches
6:14to see most of this information.
6:15We also have commands at the FortiGate, who's
6:17managing all these switches, where we can also
6:19see this information.
6:21So we clean that up a little bit.
6:22And let's go ahead and exit out of that.
6:24And let's refresh this page.
6:26All right, good, good, good.
6:27So if we hover over these links, it's
6:29going to show us the details about the ports involved.
6:31So on switch 1 is using port 9, on switch 2 is using port 9.
6:35It's showing us this speed.
6:36And we have slightly different information
6:38that's available here regarding spanning Tree Protocol,
6:40and we'll talk about that difference here
6:42in a subsequent video coming up.
6:43So this is an example of one FortiGate managing
6:46a stack of FortiSwitches.
6:48Now, in our next video, what I'd like to do
6:50is kick it up a notch and let's do HA with two firewalls acting
6:54as an HA pair that are working with a stack of switches.
6:57And we can leverage this existing stack as we currently
7:00have for that process.
7:01So I'll see you in the next video for HA.
7:03Until then, I hope this has been informative,
7:05and I'd like to thank you for viewing.
HA FortiGates and FortiSwitch
0:06And welcome back as we up the ante in each of these videos.
0:09In this video, we're going to take a look at using HA--
0:12High Availability-- with two FortiGates,
0:13managing and working with a FortiSwitch stack.
0:16So currently, we have ports a and b
0:19that are going to port 7 and 8.
0:21And here's what I propose we do.
0:22Let's take another firewall, and we'll
0:24make it an HA pair with firewall 1.
0:26And instead of using a and b going to switch 1,
0:29let's use this port a, going to the switch to port 7.
0:33Then we'll have port a down here going to the switch
0:36over on port 8.
0:36So before we're done, we'll make sure we have those connections
0:39in place physically.
0:40And as far as this failover device, this HA device,
0:43I'm not sure it's state.
0:45So let's go ahead and connect to it with a console cable.
0:47Let's wipe it out.
0:49And let's add this to firewall 1 to make the HA pair.
0:52So to make this work, we need to make sure
0:53on both firewalls we have the same connections.
0:55So we're going to have port a go down to switch 1, to port 7.
1:00And port a over here go down to port 8 on switch 1.
1:04Then for all my other connections,
1:05I have port 1 that's connecting to my home office network.
1:08So I'll make sure those two connections are
1:10in place on this second firewall after we wipe it down.
1:12So let's make a road trip over to this firewall
1:14and get it set up for HA.
1:16So this is my remote desktop session
1:18over to the computer behind me by the rack.
1:20And I'm just going to open up a terminal emulator
1:22and connect over.
1:23And let me just check my settings real quick.
1:26Actually, let's see if it works.
1:27That is not flying.
1:30Let's see what my speed is.
1:31Go ahead and do an edit.
1:32Currently, it's at 115,000 bits per second.
1:35Let's try at 9600 for the firewall.
1:37I think the switches take 115, and that's
1:39why I had it set there.
1:40Let's go to 9600, click on OK, press Enter, and nothing.
1:45Let me make sure the firewall is on.
1:47Yep, the firewall is on.
1:48It's not-- let's go ahead and just start from scratch here.
1:50I'll say, do I want to delete this?
1:52Yes.
1:52And then we right click that and delete that.
1:55Click on Yes.
1:55And let's start a new session.
1:57And we'll select serial 9600.
1:59That looks good to me.
2:00Click OK.
2:01OK, COM3.
2:02That's my USB port.
2:04All right, that looks good.
2:05So we'll go ahead and log on.
2:06And let's do an execute factoryreset.
2:09Question mark.
2:09Yep, that's it.
2:10And yes, and it is off to the races.
2:12So it's going to come back with an IP address of dot 99,
2:16because that's the default. And then
2:17we'll walk through the quick steps
2:19to set it up as an HA pair over with firewall 1.
2:22All right, so that bad boy is reset.
2:24And if you just log in real quick and change the password.
2:27All right.
2:28Let's do a get system interface.
2:30So it's just to confirm, 192.168.1.99 is where it's
2:33reachable at, at the moment.
2:34Sure enough, right there.
2:36And then we also do an execute ping,
2:37see if we can reach my default gateway here in my home office.
2:40Oh yeah, that looks good.
2:42That means I can reach that IP address from this computer.
2:44So let me go ahead and minimize that.
2:46And back at firewall 1, let's go ahead and set up for HA.
2:49And I'm also going to use my dmz interface for that purpose.
2:52So if we go to Interfaces on my firewall,
2:54I literally have an interface called dmz.
2:56So on firewall 1, we'll go to System and click on HA.
2:59And we want to say we want to be in Active-Passive.
3:02And for the device priority, the default is 128.
3:05The bigger the better.
3:06Let's go to 200.
3:07And for the group name, let's call this Cluster1.
3:09And regarding the heartbeat interface,
3:11let's go ahead and use the dmz interface.
3:14So that interface is connected with a crossover cable
3:16between firewall 1 and the second firewall
3:18that we just wiped out a moment ago.
3:20So with that selected, we'll go ahead and close
3:22and click on OK.
3:24All right, it's synchronized with itself.
3:26Woo-hoo.
3:27So let's open up a tab over to the other firewall at dot 99
3:31and have him join the party.
3:33So we'll open up a new tab.
3:34All right, it's using a self-signed certificate.
3:36So we'll go ahead and continue.
3:37We'll log in.
3:38And we'll go ahead and do this right now.
3:41I'll call this firewall 2 and optimal dashboard.
3:44So here on firewall 2, once again, we'll go to a system.
3:47Under system, we'll click on HA, and we'll
3:49say, please join the party Active-Passive with a lower
3:52priority than the other one.
3:54And the group name is Cluster1.
3:55And the heartbeat interface is going to be our dmz interface.
3:59And we'll click on OK.
4:01All right, so I'm going to go ahead and close that.
4:03And let's go back to firewall 1, and we'll
4:05bring that full screen.
4:06All right, so here at firewall 1,
4:07it says we're not yet synchronized.
4:09So if we hover over this, it's going
4:10to show us that we have a few things that
4:12are not yet synchronized.
4:13But I think they're all coming.
4:14We'll give it a few minutes to complete.
4:16All right, it's been a moment or two.
4:17Let's go ahead and see if we're getting any closer.
4:19Oh, you know what, we had five tables out of sync.
4:21Now we have one.
4:21So I think it is almost done.
4:24Looks like it's synchronizing the managed switch information.
4:26Fantastic.
4:27All right, it says it is synchronized between firewall 1
4:30and firewall 2.
4:31Fantastic.
4:31And if you go to the dashboard, let's go ahead
4:33and add a widget for HA.
4:35So we'll click on Add Widget.
4:36So we'll add one for HA.
4:38Add it.
4:39All right, so let's go take a look at our FortiSwitch.
4:41So now with HA, if we go back down to our Wi-Fi and switch
4:45controller, and then down further to Managed Switches,
4:47this is now representing our HA pair,
4:50managing this switch stack with switch 1,
4:53and then going on to tier 2 with switch number 2
4:55and switch number 3.
4:56And one of the key ideas regarding fault tolerance
4:58and high availability is that we had
5:00to test it before we need it, just
5:02to make sure it's going to do what we think it's going to do.
5:04So what I'm going to do right now
5:05is I'm going to walk back the rack
5:06and I'm going to physically pull the power from firewall
5:091, which should cause the secondary firewall to become
5:12active.
5:13And if everything works well, it should
5:15be fairly transparent to everybody involved,
5:17including the management of our switched environment.
5:20So I just physically pulled the power from firewall 1.
5:22And so as a result, firewall 2 should be now going active
5:25and supporting the network.
5:27So let me go ahead and do an F5 to reconnect.
5:29And sure enough, I'm getting a response.
5:31Click on Advanced, Proceed.
5:33And now we are logging into the secondary unit,
5:36who's now active.
5:37But from the perspective of the network and everything else,
5:40it's all good to go.
5:41So here we are at firewall 2, which is the active firewall.
5:44It's acting as the primary device.
5:46And you'll notice here in our switch management,
5:48it's showing that port 7 is down.
5:50And that's where our firewall 1 had been connected previously.
5:53So now its firewall 2 as part of the HA pair,
5:55which is physically connected to port number 8.
5:57So if we go down to HA again under System and HA,
6:01all we have now is firewall 2, who's
6:03performing the management of these switches.
6:05And not just the management, but any security policies
6:07and traffic flows that we're controlling
6:09through this firewall are now being handled by firewall 2.
6:12So right after this video is done,
6:13I'm going to go back to the rack,
6:15I'm going to power back on firewall 1,
6:16and have it become the primary again as part of the HA pair.
6:19And in the next video, I'd like to discuss with you the concept
6:22of STP and its various flavors, and how important it
6:25is in a switched environment.
6:26So we'll do that in the next video, and I'll see you there
6:28in just a moment.
6:29Meanwhile, I hope this has been informative,
6:31and I'd like to thank you for viewing.
Spanning Tree Protocol
0:07And welcome back.
0:08In this video, you and I get to chat
0:10about the reason for, and some flavors of, Spanning Tree
0:13Protocol.
0:14So let's begin with some switches.
0:16And let's go ahead and put three of them here, and two of them
0:20here.
0:21And we'll call these FSW1, 2, 3, 4, and 5.
0:27And let's imagine that these switches have trunks,
0:30and they're referred to in the world of FortiSwitch
0:32as ISLs, Inter-Switch Links, supporting 802.1 Q. Let's
0:37go ahead and do this and this.
0:41Now, the problem with this type of layer 2
0:43topology is that there's no fault tolerance.
0:45If FortiSwitch 2 fails, that means
0:47everyone over here on this portion of the network
0:49won't have access to this portion of the network.
0:51So oftentimes, we're going to have some fault tolerance
0:54by having multiple connections, including a connection, maybe,
0:56like that, and maybe one there.
0:58So multiple paths is great for fault tolerance,
1:00but in layer 2, there's no time to live mechanism
1:03inside of a layer 2 header.
1:04So we have the opportunity for one broadcast
1:07to be forwarded over and over and over throughout the network
1:09millions of times.
1:10So we need some way of stopping that from happening.
1:13And one of those ways is Spanning Tree Protocol.
1:16And there's three major flavors of Spanning Tree.
1:19The first was 802.1D.
1:21And then there's 802.1W, which is called Rapid Spanning Tree.
1:26And then one that's called 802.1s,
1:28which later was incorporated into a different standard,
1:30but they all do basically the same thing.
1:32The purpose is to identify parallel paths
1:35and then to block on one or more of those links
1:38so there is not a parallel path, and we don't
1:40have loops in the network.
1:41So let me give you the big picture regarding
1:43how Spanning Tree operates.
1:44The first rule of the road regarding Spanning Tree
1:47is to elect a root bridge.
1:49And think of the word "root," think of the root of a tree.
1:51So here is the trunk, or the root of the tree right here.
1:55And then as the tree goes out, we have branches and--
1:59it's a pretty sad tree-- but you notice the branches.
2:02They don't grow back in on each other.
2:04They only go one way.
2:05And as a result, the tree has no loops in its branches.
2:08They all go out, but they don't grow back into themselves
2:12at some other weird point.
2:13And that's what the goal of Spanning Tree
2:14is as well, to make sure we have paths to the network,
2:16but not having any loops.
2:18And the word "bridge" is a throwback
2:19to when this protocol was created, when we had bridges
2:22that performed, effectively, a layer 2 switching
2:24function, except they weren't very fast
2:26and there weren't a lot of ports.
2:27So the root bridge, think of it like the root of the tree.
2:30So let's imagine all these switches are
2:32supporting Spanning Tree.
2:33And what they're going to do is they're
2:34going to set out little BPDUs.
2:37A BPDU is a Bridge Protocol Data Unit.
2:39Think of it like the language of love
2:41that these switches are going to use
2:42and send back and forth to communicate with each other.
2:45And through the process of exchanging bridge protocol data
2:48units, they're going to find out which of these five switches
2:51has the lowest bridge ID.
2:53And the bridge ID is made up of a combination of a priority
2:56number, followed by a base MAC address.
2:58So if we wanted to artificially make one of these lower,
3:01all we'd have to do is lower the priority number,
3:03and effectively, that would lower the bridge ID, also known
3:06as a BID.
3:07And that would make it win the root bridge election.
3:09It would be the root bridge for Spanning Tree.
3:11However, if we just left the priority alone on all of these
3:14and it wasn't modified, then it boils
3:16down to which of these switches has the lowest base MAC address
3:19that's been assigned to it.
3:20So in our Spanning Tree, we're going
3:22to have one, and only one, root bridge.
3:24And so for this diagram, let's go ahead and choose
3:27switch 2 as the root bridge.
3:29Let's say it won because it has the lowest bridge ID.
3:31Congratulations, switch number 2.
3:33You are the root bridge for Spanning Tree.
3:36Next, let's talk about the losers.
3:38And you might say, Keith, what do you mean, losers?
3:40Well, if there's only one root bridge,
3:42all the other switches are losers.
3:44And that's a good way to think about it, because
3:46on each of the losers, they need to identify
3:48which one of their ports is the best
3:51one to use to forward traffic in the direction of their root
3:54bridge.
3:54And so all the losers are going to choose one root port.
3:58So I'm going to label these ports.
3:59I'm going to call this port 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11,
4:0912, and 13.
4:10And the reason we're going to use unique numbers on all
4:12these ports is just so that when we're
4:14talking about them together, we'll
4:15be very clear on exactly which port we're talking about,
4:18because no two ports in this topology
4:20have the exact same number.
4:21And I missed a port here, so we'll
4:23give this guy port number 13.
4:25So switch 2, as the root, is advertising the cost
4:28to get to itself.
4:29And no matter where you go, there you are.
4:31So the cost for switch 2 to get to itself is zero.
4:33So it's advertising 0 in BPD as going here and here
4:37and here and here.
4:39And then these other switches have
4:40a local cost associated with their interface, for example,
4:43maybe a cost of 4 here, and a cost of 4 here.
4:46And let's just say all the interfaces
4:48have a local cost of 4.
4:49So in these loser switches, the ones who are not the root,
4:52are deciding which port they should use as a root port that
4:56should be forwarding towards the root,
4:57they are going to do it based on the lowest cost.
5:00So as an exercise, let's do the math here for switch number 1.
5:02It's receiving a cost of 0 here from the root switch.
5:05And its local cost is 4.
5:07So a forwarding this direction has a cost of 4.
5:10And if we look over at switch number 3,
5:12it has a cost of 4 to get to the root.
5:14So it would be advertising the cost of 4,
5:16and so it would be a cost of 8 going here.
5:18And same thing here.
5:19Switch 4 is going to have a cost of 4.
5:21He's advertising the cost, plus the local cost.
5:23That'd be 8.
5:24So when switch 1 is making its decision about which interface
5:27should be the root port and has the lowest cost
5:29forward towards the root, it's going to choose port number 2.
5:32And that's going to be the root port.
5:34I'll put RP there.
5:35And every switch that's not the root itself
5:37is going to have one root port, which
5:39is forwarding towards the root.
5:40So we'll say RP is forwarding towards root.
5:44And based on the same logic, switch 3
5:46is going to have this as a root port.
5:47That's going to be the cheapest cost.
5:49Switch 5 is going to have this port as the root port.
5:51And switch 4 is going to have this port as the root port.
5:53So all the other switches--
5:551, 3, 5, and 4--
5:57have identified their root port based on the lowest cost
6:00to get to the root.
6:01Now there's another concept, also, as far as port roles,
6:04and that's called a designated port.
6:06And a designated port is forwarding frames at layer 2
6:08and forwarding away from the root.
6:11And each network segment between two switches
6:13has to have at least one designated port.
6:15So the root bridge, because it's the root, all of its ports
6:18are going to be designated.
6:20They're all forwarding away from itself.
6:22So this is going to be a designated port.
6:24That's a designated port.
6:25That's the designated port.
6:26That's a designated port.
6:27And again, for each segment of the network
6:29there needs to be one designated port that's forwarding
6:31traffic away from the root.
6:32So these four links that switch 2
6:35is directly connected to all have designated ports.
6:38So I'll put one per segment here.
6:39Now, where it gets a little bit tricky with designated ports
6:42is between switch 4 and switch 5.
6:44And let me add the Ws there.
6:46I'm not sure why I forgot those earlier.
6:47So one of these two switches needs
6:49to be the designated switch for this segment right here.
6:53And so as far as who gets to be the designated
6:55port for that segment, it's going
6:56to be which switch has the lowest cost, so lowest
6:59cost to get to the root.
7:00So currently switch 4 has a cost of 4 to get to the root.
7:04And switch 5 has the cost of 4 to get to the root.
7:06So that's a tie.
7:07And if that's a tie, which it is in this topology,
7:09the next thing they would use is which
7:11of these two switches, switch 4 or switch five,
7:13has the lowest bridge ID, because those
7:16are going to be unique.
7:17So let's manage that switch 5 wins that because it
7:19has the lowest bridge ID.
7:20It would then be the designated port for that segment.
7:23And so each segment is going to have one
7:25and only one designated port.
7:26So then we have that same problem here between switch 3
7:29and switch 5.
7:29Which of these two devices has the lowest cost?
7:31If they both have a cost of 4 to get to the root,
7:34then it's going to be based on lowest bridge ID.
7:36And let's imagine that switch 5 also wins that.
7:38So that's going to be a designated port.
7:40And then we have the same scenario here between switch 4
7:42and switch 1.
7:43So let's match that switch 1 has the lower bridge ID,
7:46so it becomes the designated port.
7:48And then we have one more that we haven't identified
7:50and that's between switch 1 and switch 3.
7:52And they both have a cost to 4 to get to the root.
7:54So let's imagine that switch 1 has a lower bridge ID, the tie
7:56breaker, between switch 1 and switch 3.
7:59And as a result, it becomes the designated port.
8:01So just as a quick check, the root bridge, all of its ports
8:05are designated.
8:06They're all forwarding away from itself.
8:07So that takes care of this segment, this segment,
8:10this segment, and this segment.
8:11We identified the winner for this segment, which
8:13is switch 5, the winner for this segment, which is switch 1,
8:16and the winner for this segment, which is switch 1, also.
8:19And
8:20Then the final step is to take any
8:21of these connections between switches, which
8:23aren't designated ports or not root ports,
8:26and those will end up being blocked.
8:28So this port 5 on switch 3 would end up as being blocked.
8:31And this port here would be blocked.
8:33And this port here, port 9, would be blocked.
8:36And that addresses the entire topology.
8:38So effectively, we have a tree as a result of Spanning Tree.
8:42So this is the original flavor of Spanning Tree.
8:45This is referred to as Rapid Spanning Tree.
8:47And Rapid Spanning tree has some improvements
8:49regarding conversions.
8:50If there's a change it handles it better, it converges faster.
8:53And some of the terms are different between STP
8:56and rapid STP.
8:56For example, with STP they had a concept called blocking,
8:59which is what's happening right here.
9:01It's blocking on that port from a Spanning Tree perspective.
9:03So we don't have a loop.
9:04However, in Rapid Spanning Tree, that's
9:06referred to as discarding.
9:07However, at the end of the day, it's the same function.
9:10We're not forwarding frames out this port
9:12because it's in a blocking, or with Rapid Spanning
9:15Tree, a discarding state.
9:16Now, at Cisco Systems, they implement something
9:18called Per-VLAN Spanning Tree.
9:20And with Per-VLAN Spanning Tree, if you have 20 different VLANs,
9:24you have 20 different instances of Spanning Tree.
9:27Now, there's another standard called Multiple Spanning Tree,
9:30which is often written as MST, which was the original standard
9:33of 802.1s.
9:34And what it does, it creates Spanning Tree instances.
9:37So it has a Spanning Tree instance of zero,
9:39and by default all the VLANs mapped to that same instance.
9:44So instead of having, for example,
9:4520 VLANs and 20 separate instances of Spanning Tree,
9:49you can have, for example, instance one and instance two.
9:52You can say, I want VLANs 2 through 19
9:55to map to that instance.
9:56And VLANs 20 through 29 to map to that instance.
10:00And then you have a lot less overhead
10:02using multiple Spanning Tree.
10:04Think about multiple VLANs mapping to the same Spanning
10:07Tree.
10:07And here's the takeaway with FortiSwitch.
10:09By default, in the background, they
10:11are running MST, which has all the bells and whistles
10:14and benefits of Rapid Spanning Tree,
10:16plus the benefit of using less instances compared
10:19to Per-VLAN Spanning Tree.
10:21And the whole discussion regarding the details of 802.1s
10:25would take an entire another course.
10:27And what I want you to take away from this discussion
10:29is the idea that Spanning Tree has
10:32the purpose of identifying parallel paths in a layer 2
10:35network and then implementing blocking on one or more ports
10:39to prevent a layer 2 loop.
10:41And that's true with or 802.1D, 802.1w,
10:45as well as Multiple Spanning Tree.
10:47And to help reinforce that, I brought back
10:49Firewall 1 as my primary firewall in the HA pair
10:52here in the topology view regarding
10:54managed FortiSwitches.
10:55If we hover over an interface here, you notice in the output
10:58under STP status, it says forwarding,
11:00and the same thing here for port 10
11:02is forwarding from an STP status perspective.
11:04And we have a link between here and here,
11:06between switch 2 and switch 3, that would be a layer 2 loop.
11:10And Spanning Tree would identify that, and as a result,
11:12one of these ports would be designated and forwarding,
11:15and the other would be blocked.
11:17Or with Rapid Spanning Tree and MST,
11:19it'd be referred to as discarding.
11:21And what I discovered is that on this switch right
11:23here, which is a 108E with current firmware,
11:26it reports that forwarding state accurately.
11:29And on my older switches here that I purchased used--
11:32I think they're running like 3.6.11--
11:34the output here in the topology view
11:36doesn't always accurately reflect
11:38what the actual Spanning Tree state is.
11:40But what we can do is we can go to the CLI on the FortiGate,
11:43and we can get that Spanning Tree information
11:45from those switches.
11:46So here on the FortiGate, let's go to the CLI on the FortiGate.
11:49And let's get our list of switches with an execute switch
11:53controller, get-conn-status and press Enter.
11:55So there's our three switches.
11:57And let's take a peek at Spanning Tree for switch number
11:591, which is the root of our Spanning Tree.
12:01So all of its ports should be designated and forwarding.
12:04So to see that here at the FortiGate interface,
12:07we'll do a diagnose switch controller,
12:09switch info STP, then we'll go and copy
12:11and paste that switch ID in.
12:13So that's switch number 1.
12:14We'll press Enter.
12:15And so here is MST instance 0.
12:19There's also instance 15, which it
12:21created to support VLAN 4094, which
12:24is the VLAN being used for the management of the switch stack.
12:26And in both cases, it's showing that this bridge is the root,
12:29this is switch 1, and all of the ports that are enabled
12:31are designated, and they're also forwarding.
12:34So if we did that same command-- let's
12:36go ahead and hit the up arrow key a couple of times.
12:38And let's do it for this switch right here.
12:40I'll go ahead and copy that ID, and then hit the up arrow
12:42key a couple of times.
12:43And we'll look at this for a switch number 2.
12:45So that's switch 2's ID.
12:46We'll press Enter.
12:47And you'll notice it has a root port for instance 0 of MST,
12:52and also for instance 15 for the management.
12:54It also has a root port.
12:56And we also see the same thing for switch number 3.
12:59So if we take a look at switch number 3,
13:01let's go ahead and copy its switch ID here,
13:03and hit the up arrow key a couple of times,
13:05and then paste that ID in.
13:06It also has a root port, both for instance 0,
13:09and also for instance 15.
13:11So every non-root bridge, in this case,
13:14it's switch 2 and switch 3, they're
13:16going to have a root port that's doing forwarding
13:18towards the root bridge.
13:19And if we want to close that, we can see once again, right here,
13:22the graphical representation of that.
13:24So thanks for joining me in this discussion regarding
13:26FortiSwitch topologies and an overview
13:28of Spanning Tree Protocol.
13:30And I'll see you, my friend, in another video soon.
13:32Until then, I hope this has been informative,
13:35and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year