Sora Yazılım
English
Custom software solutions from Türkiye

What Is FortiSwitch? A FortiLink Managed Switch Selection Guide

FortiSwitch is Fortinet's family of managed enterprise switches that connect to a FortiGate firewall over the FortiLink protocol and behave as a logical extension of it. VLANs, ports, PoE and access policies are managed from the FortiGate interface without a separate switch console; the right model is chosen by port count, PoE budget, uplink speed and the management capacity of your existing FortiGate.

What is FortiSwitch and how does it differ from a classic managed switch?

FortiSwitch is Fortinet's enterprise access and campus switch family. Its fundamental difference from a classic managed switch is that, once connected to a FortiGate over FortiLink, it stops being an independent network device and becomes part of the firewall's policy engine. The wired access layer thereby falls under the same visibility and control as the perimeter.

In a classic deployment the switch has its own operating system, its own management IP, its own user accounts and its own backup routine. The firewall, in turn, does not know which device is plugged into which port; it only sees the traffic that reaches it. FortiSwitch removes that disconnect: port, VLAN, PoE and authentication information is consolidated on the FortiGate. The user, application and threat context carried by the FortiGate firewall is pushed straight down to the access port.

The Fortinet portfolio has two main series. The Secure Access series (108F, 124F, 148F, 124G and similar) delivers up to 48 access ports in a 1 RU chassis with uplinks up to 10GE and targets branch and wiring-closet scale. The Secure Campus series (500, 600, 1000 and T1000) offers uplinks up to 100GE and higher PoE budgets for campus distribution and core layers. This guide focuses on the Secure Access series, which SMBs and mid-sized organizations evaluate most often. For a current overview of the family, see our FortiSwitch solution page.

FortiSwitch runs in three management modes: FortiLink (through the FortiGate), standalone (classic switch management) and FortiEdge Cloud (multi-site management from the cloud). If a FortiGate is present, FortiLink is the default choice, and the rest of this guide assumes that scenario.

How does FortiLink work and what does single-pane management deliver?

FortiLink is the protocol that attaches a FortiSwitch to the FortiGate's management plane. A switch connected to the FortiLink interface is discovered and authorized automatically; from then on VLAN definition, port assignment, PoE on/off, trunk configuration and firmware upgrades are performed from the FortiGate interface. No separate switch console, no separate configuration backup and no separate CLI expertise are required.

The gain is more than "one console fewer". Because security policy and network configuration live in the same place, isolating a user group or moving a device class to another segment no longer requires coordinating two teams. In our field experience this noticeably reduces operational load in SMBs with one- or two-person IT teams: the answer to "who changed what, and when" on the switch side is already in the FortiGate event log.

FortiLink topologies scale from a single switch to multi-tier designs. Switches can be daisy-chained or connected in a star; where high availability matters, two FortiSwitches form an MCLAG pair and downstream switches attach to that pair with dual uplinks. According to Fortinet documentation, a three-tier FortiLink MCLAG topology requires FortiOS 6.2.3 and FortiSwitchOS 6.2.3 or later, and tier-2 and tier-3 MCLAG peer groups can be deployed from the FortiGate switch controller without console access to the switches (Fortinet FortiLink Guide, MCLAG topologies).

If the FortiGate itself is an HA pair, FortiLink attaches to the pair; when the primary unit fails, switch management moves to the secondary. This means the access layer must be included in scope when firewall high availability is designed; our FortiGate HA configuration guide covers the details.

Which FortiGate manages how many FortiSwitches?

The number of FortiSwitches a single FortiGate can manage ranges from 8 to 300 by model (Fortinet FortiSwitch Secure Access data sheet, 2026). The FortiGate 40F manages 8, the 60F/70G/80F/90G 24, the 100F 32, the 120G 48, the 200F 64, the 400F 96, the 600F 128, the 900G 196, and high-capacity FortiGate-VM instances 300. These are upper limits; leave headroom for growth.

The table below lists the verified maximums from the official data sheets of the relevant FortiGate models together with the FortiLink interface type. Remember that the same FortiGate also manages FortiAP access points at the same time; both capacities must be evaluated together.

FortiGate modelMax. managed FortiSwitchesMax. FortiAPs (total / tunnel)FortiLink interface and notes
FortiGate 40F816 / 81x GE RJ45 FortiLink; micro office
FortiGate 60F2464 / 322x GE RJ45 FortiLink
FortiGate 70G2496 / 482x GE RJ45 FortiLink
FortiGate 80F2496 / 48On the 80F-PoE the FortiLink ports supply PoE/PoE+
FortiGate 90G24128 / 64Branch and small campus
FortiGate 100F32128 / 642x 10GE SFP+ FortiLink
FortiGate 120G48128 / 644x 10GE SFP+; 48 requires FortiOS 7.6.1+, 32 on earlier releases
FortiGate 200F64256 / 1282x 10GE SFP+ FortiLink
FortiGate 400F96512 / 256FortiOS 7.6.1+
FortiGate 600F1281,024 / 512FortiOS 7.6.1+
FortiGate 900G1962,048 / 1,024FortiOS 7.6.1+
FortiGate-VM (VM-08S and above)300Virtual instance

Two practical conclusions follow. First, on entry-level models (40F–90G) the FortiLink interface is 1 Gbit RJ45; in designs where all access-layer traffic passes through the firewall, that link can become the bottleneck. The 100F, 120G and 200F remove that limit with 10GE SFP+ FortiLink ports. Second, the maximums for the 120G, 400F, 600F and 900G are stated for FortiOS 7.6.1 and later; a 120G on an older release manages 32 switches, not 48. Do not size capacity before the upgrade is planned.

To see which FortiGate fits which office in detail, read our FortiGate 40F, 60F, 70G and 90G comparison, and for the overall framework of firewall selection our firewall selection guide for SMBs. The complete model family is listed on our FortiGate solution page.

How do you size port density and PoE budget?

PoE budget is defined by SKU selection, not by the model name: every series has non-PoE, half-PoE (-POE) and full-PoE (-FPOE) variants, and Fortinet publishes a separate "PoE Power Budget" value for each SKU. The correct method is to add up the actual draw of the real device list (access points, IP phones, cameras, IoT) rather than assume every port is loaded, and then add headroom for growth.

Port density has three inputs: ports per user, the list of PoE-powered devices and uplink capacity. In the Secure Access series the FS-108F offers 8 ports with 2x GE SFP uplinks, the FS-124F 24 ports with 4x 10GE SFP+ uplinks and the FS-148F 48 ports with 4x 10GE SFP+ uplinks. A single 48-port unit is efficient in rack space and management, but a single failure takes the whole floor down. On floors with low outage tolerance, two 24-port switches with uplinks over independent paths are the safer design.

Model (SKU)PoE portsTotal PoE budgetUplinkTypical use
FS-108F-POE / FS-108F-FPOE8x 802.3af/at65 W / 130 W2x GE SFPSmall office, a few APs and phones
FS-124F-POE12x 802.3af/at (ports 1–12)185 W4x 10GE SFP+Wiring closet, mixed load
FS-124F-FPOE24x 802.3af/at370 W4x 10GE SFP+Floor needing PoE+ on every port
FS-148F-POE / FS-148F-FPOE24x / 48x 802.3af/at370 W / 740 W4x 10GE SFP+Dense floor, IP phones + APs
FS-124G-FPOE8x 802.3bt (90 W) + 16x 802.3af/at (30 W)780 W6x 10GE SFP+ (2.5GE access ports)Floor with Wi-Fi 7 APs and PTZ cameras
FS-548D-FPOE48x 802.3af/at750 W (single PSU) / 1,440 W (dual PSU)Campus classDistribution layer, redundant power
FS-348G-FPOE48x 802.3bt type 41,540 WCampus classDense PoE++ deployment

The values are the maximum PoE output stated in the Fortinet FortiSwitch Secure Access and Secure Campus data sheets (2026); they do not mean every port receives maximum power simultaneously. On half-PoE (-POE) SKUs only part of the ports are powered: the first 12 on the FS-124F-POE and the first 24 on the FS-148F-POE. The FS-548D-FPOE is worth noting: the second power supply buys not only fault tolerance but usable PoE budget. On PoE-heavy floors, a design calculated with a single PSU can hit the ceiling during commissioning.

The PoE standard also drives the choice. 802.3af/at (PoE/PoE+) delivers 30 W per port and is sufficient for IP phones, fixed cameras and 802.3at-class access points. 802.3bt (PoE++) delivers 90 W per port; Fortinet's Wi-Fi 7 flagship models FAP-441K and FAP-443K require 10 Gigabit Ethernet ports and 802.3bt power (Fortinet FortiAP Series data sheet, 2026). Both requirements appear together on the switch side: an 802.3bt port and access speed above 1 Gbit. We cover the wireless side in our FortiAP and enterprise Wi-Fi selection guide; when FortiAP access points and FortiSwitch are designed together, both line items land in the same calculation.

FortiSwitch selection criteria: a 7-point checklist

FortiSwitch selection becomes clear once seven questions are answered: the management capacity and FortiLink interface speed of your existing FortiGate, required port count, PoE device list and standard, uplink speed, redundancy needs, management mode and support term. This checklist prevents choosing the wrong SKU at quotation time and the surprises that surface during commissioning.

#CriterionQuestion to askConsequence of a wrong choice
1FortiGate capacityHow many switches and APs can the current FortiGate manage, and which ceiling does its FortiOS release support?The management limit is exceeded as switches are added; a firewall replacement comes onto the agenda
2FortiLink interface speedIs the FortiLink port 1 GE or 10 GE?Access-layer traffic congests on the single link to the firewall
3Port countUsers, printers, APs and cameras per floor; three years of growth?A second unit is added to a full switch and cabling is done twice
4PoE budget and standardWhich devices need 802.3at, which need 802.3bt; what is the total actual draw?Devices lose power in turn or run in low-power mode
5Uplink1 GE or 10 GE from closet to distribution; are there two independent paths?A 48-port switch bottlenecks on a single 1 GE uplink
6RedundancyAre dual PSUs, an MCLAG pair or FortiGate HA required?A single failure takes down the whole floor or branch
7Management mode and supportFortiLink or FortiEdge Cloud; what are the FortiCare term and RMA conditions?The wrong mode increases operational load; firmware updates stop when support lapses

Criteria four and five are linked. A design that only checks the PoE budget and ignores port speed cannot capitalize on the Wi-Fi 7 investment; a design that only checks port speed and skips the PoE calculation leaves access points running in low-power mode. In our projects we derive both items device by device in a single table.

The seventh criterion is frequently overlooked. FortiSwitch hardware ships with a FortiCare support contract; when the contract expires the unit keeps running, but FortiSwitchOS updates and RMA entitlement end. A switch usually outlives the firewall in service, so aligning the support term with the FortiGate license cycle consolidates renewals on one date.

Segmentation and NAC at the access layer

FortiLink integration brings four capabilities that the Fortinet data sheet describes as basic NAC at no additional cost: device profiling, automatic segmentation for IoT, port quarantine on violation and virtual patching for devices that cannot be updated. These work as a continuation of FortiGate policy without a separate NAC server, a separate console or a separate operational burden.

What limits malware on one endpoint from spreading across the whole LAN is not the perimeter firewall but the segmentation enforced on the switch that the user port is connected to. When printers, IP cameras, access-control panels and IP phones are recognized by profiling and placed automatically into defined segments, they no longer share a broadcast domain with the user network. A device behaving outside policy is isolated on its port; the response does not wait for an engineer to walk to the closet and pull the cable.

On the authentication side, FortiSwitch supports, as listed in the data sheet, port-based and MAC-based 802.1X, MAC Access Bypass (MAB), dynamic VLAN assignment based on RADIUS attributes (RFC 4675) and RADIUS CoA. The identity source can be the organization's existing RADIUS/NPS infrastructure or FortiAuthenticator. The important distinction: FortiLink NAC port-security automation does not mandate 802.1X. Organizations without an 802.1X infrastructure can start with profile-based segmentation and introduce 802.1X later, first in monitor mode and then in enforcement mode.

A common mistake in segmentation design is to confuse adding VLANs with segmenting. What separates segments is not the VLAN tag but the inspection of traffic between them. That is exactly where positioning FortiSwitch alongside FortiGate pays off: inter-segment traffic passes through the same policy and the same security profiles as perimeter traffic. For audit and compliance, you must be able to show from records which device sits in which segment and how inter-segment traffic is inspected; FortiAnalyzer provides that evidence layer. For KVKK and similar obligations, we recommend verifying current legislation and official guidance.

How does procurement and deployment proceed?

FortiSwitch procurement and deployment runs in five steps: inventory and topology capture, design of the target segmentation model on the FortiGate, SKU selection and quotation, commissioning of a pilot floor over FortiLink, and phased migration of the remaining floors after validation. Migration is not a weekend swap of every switch but a staged project that proceeds floor by floor.

1. Inventory. Unregistered switches in wiring closets, undocumented VLANs, legacy PBX connections still in production and IoT devices with no known owner typically surface at this stage. We treat inventory as the project's first deliverable rather than a pre-migration formality; the segmentation model can only be built on an accurate inventory. The PoE device list is produced in this step as well.

2. Design. The target VLAN and segment plan, FortiLink topology (single switch, chain, MCLAG), uplink paths and the 802.1X phasing are defined. The management capacity and FortiOS release of the existing FortiGate are verified here; if needed, a firewall refresh is added to the project.

3. SKU selection and quotation. Port count, PoE class, uplink type and FortiCare term are finalized. These are the items that determine cost; because the amount depends on the device inventory and support scope, the quotation is prepared per project. Since the Fortinet portfolio is updated at SKU level, the current official data sheet of the selected SKU is re-confirmed for every project (Fortinet FortiSwitch Secure Access data sheet).

4. Pilot floor. Two criteria guide pilot selection: representative user density and no critical business process on that floor. The validation list covers FortiLink discovery and authorization, VLAN and trunk assignments, PoE devices coming back cleanly after reboot, voice traffic prioritization, the 802.1X flow and failover across the redundant uplink. For the groundwork on the FortiGate side, our FortiGate installation and initial configuration guide shows the way.

5. Phased migration and handover. The remaining floors are migrated in sequence; each phase's output is delivered in writing and a rollback plan is defined in advance. At project close-out the configuration document, port-to-device map and support contract calendar are handed over.

A single-vendor LAN is not the right choice in every environment. In projects where budget is the deciding constraint, or raw port density matters more than security integration, we also evaluate alternatives such as the Ruijie RG-NBS enterprise switch family. The decision criterion is clear: if a FortiGate-centered security architecture is being built and policy consistency at the access layer is required, the return on FortiSwitch is high.

Frequently Asked Questions

Does FortiSwitch require a separate license?

No separate license is needed for FortiLink management and basic NAC; these functions come with the FortiGate switch controller. The hardware is sold with a FortiCare support contract that covers firmware updates, technical support and RMA entitlement. When it expires the switch keeps running, but update and replacement rights end.

What is the difference between FortiLink mode and standalone mode?

In FortiLink mode the switch is controlled by the FortiGate; VLANs, ports, PoE and access policies are managed from its interface and basic NAC is active. In standalone mode the switch is configured from its own interface like a classic managed switch. Standalone suits sites without a FortiGate.

How many FortiSwitches can a FortiGate 60F manage?

According to the Fortinet data sheet, the FortiGate 60F manages up to 24 FortiSwitches and 64 FortiAPs (32 in tunnel mode); its FortiLink interface is 2x GE RJ45. That is an upper limit; because the 60F also performs security inspection and VPN termination, leave headroom for growth in the design.

Is PoE++ mandatory for Wi-Fi 7 access points?

Fortinet's Wi-Fi 7 flagship models FAP-441K and FAP-443K require a 10 Gigabit Ethernet port and 802.3bt PoE; a 30 W port is not sufficient for them. Elsewhere in the FortiAP portfolio the requirement varies between 802.3at and 802.3bt, so check each model's data sheet.

One 48-port switch or two 24-port switches?

A single 48-port unit saves rack space, but one failure means a floor-wide outage. The PoE budget also enters the decision: the FS-124F-FPOE offers 370 W, the FS-148F-FPOE 740 W. Where outages are costly, two units with independent uplink paths are safer.

How long does migration from existing Cisco or HPE switches take?

Duration depends on the number of wiring closets and how well the inventory is documented. The deciding item is inventory and segmentation design, not the switch swap. We run four phases: inventory, target model, pilot floor and phased migration, each with a predefined rollback plan.

How is the FortiSwitch price determined?

Price is determined by port count, PoE class (non-PoE, -POE, -FPOE), uplink type, series (Secure Access or Secure Campus) and the FortiCare support term. Because these vary per project we publish no fixed figure; from your device inventory and floor plan we prepare a quotation with model recommendation and PoE calculation.

Conclusion

In a FortiGate-centered security architecture, FortiSwitch ties the access layer to the same policy set as the perimeter: one interface, basic NAC without an extra license, port-level segmentation. The selection decision reduces to four numbers: how many switches your existing FortiGate can manage, ports needed per floor, the PoE budget derived from the real device list and the uplink speed. When these four are right, the SKU choice follows on its own.

Let us work out together how many switches with how many ports you need, how your PoE budget comes out of the real device list and how many switches your current FortiGate can manage. Share your existing topology and device inventory, and we will prepare a design document and quotation covering the segmentation model, model recommendation and migration plan. You can request a free discovery call through our contact page.

Need help with the topics in this post?

Schedule a free discovery call with Sora Yazılım — we'll propose a concrete roadmap.

WhatsApp Support