LESSON 01: Managed Switch Flashcards

In this lesson, you will learn about FortiSwitch essentials, focusing on the managed switch mode. (49 cards)

1
Q

What is FortiSwitch?

A

This is Fortinet’s ethernet switch which operates at layer 2 of the OSI model.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What OS does FortiSwitch run?

A

FortiSwitchOS

Fortiswitch OS is based on FortiOS Kernel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What interface is used to manage FortiSwitch on a FortiGate?

A

Fortilink Interface

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the three (3) use cases for FortiSwitches?

A
  1. Secure Access
  2. Datacenter
  3. Rugged
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the three (3) management modes for FortiSwitch?

A
  1. Standalone
  2. Managed Switch
  3. FortiLAN Cloud
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

When Fortiswitch is deployed in managed mode, what device acts as the controller?

A

The Fortigate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Key benefits of managing FortiSwitch devices using FortiGate

A
  1. Zero-Touch Provisioning
  2. Secure Configuration Management
  3. Centralized Provisioning and Maintenance
  4. Fortiswitch Stacking
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is zero-touch provisioning in FortiSwitch management?

A

Administrators only need to connect FortiSwitch to a FortiGate interface with FortiLink enabled. FortiGate then automatically discovers and provisions FortiSwitch.

If FortiManager is used, zero-touch provisioning can also be achieved by configuring the FortiGate settings on FortiManager.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How is secure configuration management handled in FortiSwitch?

A

All FortiSwitch management is done on the FortiGate GUI and CLI, or on FortiManager if used. Administrators do not need to log in to FortiSwitch.

This enhances security and simplifies management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does centralized provisioning and maintenance mean for FortiSwitch?

A

FortiSwitch becomes an extension of FortiGate, allowing configuration of firewall policies for FortiSwitch VLANs in the same way as FortiGate VLANs.

Authentication and authorization are also handled centrally on FortiGate or FortiManager.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a FortiSwitch stack?

A

FortiGate can manage multiple FortiSwitch devices stacked in different ways to offer scalability and redundancy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What must be enabled on FortiGate to manage FortiSwitch stack?

A

Switch controller feature

This feature allows FortiGate to discover and manage connected FortiSwitch devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What must be checked for compatibility between FortiSwitch and FortiGate?

A

FortiSwitchOS version and FortiOS version

Compatibility can be verified using the compatibility matrix available on docs.fortinet.com.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Is the switch controller feature enabled by default on all FortiGate models?

A

No, it is not enabled by default on FortiGate VM models

Most other FortiGate models have this feature enabled by default.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How can the switch controller feature be enabled on FortiGate VM models?

A

By running specific CLI commands

These commands are provided on the relevant slide.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Where can you find the related switch controller settings after enabling the feature?

A

Under the WiFi & Switch Controller section in the GUI

If not visible, check the Feature Visibility page.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What should you do if the GUI settings for switch controller are not displayed?

A

Ensure the Switch Controller feature is enabled on the Feature Visibility page

This step is crucial for accessing the settings.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is the default VLAN assigned for switch management traffic?

A

VLAN 4094

VLAN 4094 is configured as the native VLAN on various links.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What type of traffic is exchanged untagged on switches?

A

Switch management traffic

This traffic is assigned to VLAN 4094 by default.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is VLAN 4094 configured as on the FortiLink trunk?

A

The native VLAN

It is also configured as the native VLAN on inter-switch links (ISLs) and inter-chassis links (ICLs).

21
Q

What are ISLs and ICLs

A

Inter-switch links (ISLs) and inter-chassis links (ICLs)

VLAN 4094 is the native VLAN for both ISLs and ICLs.

22
Q

True or False: VLAN 4094 is not used for inter-chassis links.

A

False

VLAN 4094 is used as the native VLAN for inter-chassis links (ICLs).

23
Q

What is the factory default FortiLink interface named in FortiGate devices that support the switch controller feature?

A

fortilink

This interface is located in the root VDOM.

24
Q

What type of interface is the default FortiLink interface?

A

link aggregation group (LAG) interface

No LAG members are assigned by default.

25
What roles does FortiGate perform for the managed switches by default?
default gateway, DHCP server, DNS server, NTP server ## Footnote FortiGate provides these services automatically.
26
What must be done before managing switches that FortiGate discovers by default?
Authorize the switches ## Footnote Alternatively, devices can be automatically authorized.
27
What is the consequence of disabling the FortiLink split interface when connecting to switches?
You lose management of one or more switches ## Footnote This occurs if the switches do not support MCLAG.
28
Fill in the blank: The default FortiLink interface requires the administrator to _______ the LAG members manually.
add ## Footnote This is necessary because no members are assigned by default.
29
What protocol does FortiGate use by default for switch discovery?
FortiLink ## Footnote FortiLink discovery frames include the switch serial number and port information.
30
What information is included in FortiLink discovery frames?
Switch serial number and port information ## Footnote Only specific ports send FortiLink discovery frames in standalone mode.
31
Which alternative switch discovery method can be used alongside FortiLink?
LLDP ## Footnote LLDP is used for setting up switch stacks and automatically configuring trunk links.
32
What does LLDP enable when setting up a switch stack?
Automatic configuration of links as trunks (auto-ISL) ## Footnote This feature simplifies the setup of multi-switch environments.
33
What is the role of CAPWAP in FortiGate's management of FortiSwitch devices?
Switch authentication, authorization, and health checks ## Footnote CAPWAP establishes a DTLS tunnel for secure communication.
34
What type of tunnel does CAPWAP establish between FortiGate and the switch?
Datagram Transport Layer Security (DTLS) tunnel ## Footnote This tunnel secures the communication for authentication and health checks.
35
What additional information does FortiSwitch send to FortiGate using CAPWAP?
LLDP neighbor information and switch logs ## Footnote This helps in monitoring and managing the switch more effectively.
36
Why is the use of NTP important for FortiGate and FortiSwitch?
To ensure that the time is in sync; otherwise, the CAPWAP DTLS tunnel won’t be established.
37
What happens if the time on FortiGate and FortiSwitch is not in sync?
The CAPWAP DTLS tunnel won’t be established and the switch won’t come online.
38
What is the default firmware upgrade method on a managed switch?
https
39
What protocol does Foritgate use to inform FortiSwitch of its Authorization?
Fortilink
40
What FortiSwitchOS CLI setting controls the automatic broadcast of FortiLink discovery frames on a switch?
"auto-discovery-fortilink"
41
What happens to the switch configuration when a switch in standalone mode is authorized?
The switch configuration is saved locally before changing to FortiLink mode ## Footnote This allows for restoration of the previous configuration if the management mode is changed back to standalone.
42
Where is the configuration for a managed switch stored?
On FortiGate, as part of the FortiOS configuration file ## Footnote This includes configuration revisions and backups made by the administrator.
43
How is the configuration pushed to a managed switch from FortiGate?
Using the FortiSwitch REST API ## Footnote The push follows an asynchronous model.
44
What is the consequence of making configuration changes directly on the switch?
Configuration changes made directly on the switch are not synced to FortiGate and may be lost ## Footnote Therefore, making changes directly on the switch is not recommended.
45
How does FortiGate handle configuration pushes for a managed switch after authorization?
FortiGate pushes the complete configuration only once after switch authorization, then only the delta configuration for changes made by the administrator ## Footnote Delta configuration refers to only the changes made since the last push.
46
What triggers FortiGate to push delta configuration to a switch?
When the switch status changes from offline to online, provided there were changes made while it was offline ## Footnote Status changes can occur due to reboot, firmware upgrade, or network disconnection.
47
What is the benefit of FortiGate pushing configuration to multiple managed switches at the same time?
Improves performance and scalability ## Footnote This allows for efficient management of multiple switches.
48
What protocol does FortiSwitch use to export logs to Fortigate?
CAPWAP
49
What is the default log severity level used by FortiSwitch to export logs to Fortigate?
Information