Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · Network Security

FortiSwitch

Enterprise PoE access switch family managed from FortiGate via FortiLink.

Quick answer

FortiSwitch is the family of managed enterprise switches that connects to the FortiGate firewall through the FortiLink protocol. VLANs, ports, PoE and access policies are managed from the FortiGate interface without a separate switch console. A single FortiGate can manage between 8 and 300 FortiSwitches depending on the model; the FortiLink integration adds basic NAC capabilities at no extra cost.

FortiSwitch is the family of managed enterprise switches that connects to the FortiGate firewall through the FortiLink protocol and behaves like a logical extension of the firewall. VLAN definitions, port configuration, PoE supply and access policies are managed from the FortiGate interface without ever opening a separate switch console. A single FortiGate can manage between 8 and 300 FortiSwitches from one place, depending on the model (Fortinet FortiSwitch Secure Access data sheet, 2026).

The access layer is the most frequently neglected link in an enterprise security architecture. According to Verizon's 2025 Data Breach Investigations Report, ransomware was present in 44% of the breaches analysed; among small and medium-sized organizations that figure rose to 88% (Verizon DBIR, 2025). What limits the spread of malware from one endpoint across the entire local network is not the perimeter firewall but the segmentation and access control applied on the switch that the user port is connected to. FortiSwitch delivers that control as a natural continuation of FortiGate policy, without the need to buy a separate NAC product.

What is FortiLink, and what do you gain by managing FortiSwitch from FortiGate?

FortiLink is the protocol that attaches FortiSwitch to FortiGate's management plane. In this mode the switch stops being an independent network device and behaves like a remote port group of the firewall: VLAN definitions, port assignments, enabling and disabling PoE ports, trunk configuration and firmware updates are all done from the FortiGate interface. There is no need to maintain a separate management IP, a separate CLI session or a separate configuration backup routine. Fortinet states that FortiLink turns the switch into a logical extension of FortiGate and that between 8 and 300 switches can be managed this way depending on the FortiGate model (Fortinet, 2026).

The gain is not merely a smaller number of consoles. Because security policy and network configuration are defined in the same place, isolating a user group or moving a device class to a separate segment does not require two different teams to coordinate. Since the FortiGate firewall family already carries identity, application and threat context, the switch port inherits that context directly. In practice this means the question "who, on which device, is reaching which resource at the access layer?" can be answered from a single place. In classic deployments that information sits scattered across the switch MAC table, RADIUS logs and the firewall session table.

The FortiLink integration also brings a basic network access control (NAC) layer that requires no additional payment. Fortinet's FortiSwitch Secure Access data sheet defines that layer under four headings (Fortinet, 2026):

  • Device profiling: the type and behaviour of every device connecting to the network is classified automatically; a device that is not in the inventory becomes visible the moment it is plugged into a port.
  • Automatic segmentation for IoT: devices such as printers, cameras, access control panels and IP phones are placed into defined segments by themselves; they do not remain in the same broadcast domain as the user network.
  • Quarantine on violation: a device behaving outside policy is isolated on the port it is connected to, preventing lateral movement until the incident is investigated.
  • Virtual patching: for legacy devices that cannot be updated, protection is applied at the network layer; an HMI on a production line or an end-of-life medical device is the typical target of this approach.

All of these components run within the Fortinet Security Fabric architecture. Fortinet states that the Security Fabric provides unified visibility across an ecosystem covering more than 500 third-party solutions in addition to its own products, and that more than 1,000,000 customers worldwide use Fortinet solutions (Fortinet corporate information, 2026). Leaving the switch layer outside this architecture means leaving the layer that the largest number of devices connect to outside your visibility.

How many FortiSwitches can one FortiGate manage?

Between 8 and 300 FortiSwitches can be managed from a single FortiGate, depending on the model (Fortinet FortiSwitch Secure Access data sheet, 2026). The lower bound applies to small virtual instances and the upper bound to high-capacity virtual FortiGates. A point often overlooked in capacity planning is that the same FortiGate is simultaneously managing FortiAP access points; the two figures must be evaluated together. The table below shows the upper limits verified against the official Fortinet data sheets for the relevant models.

FortiGate modelMax. managed FortiSwitchMax. FortiAP (total / tunnel mode)FortiLink interface and note
FortiGate 60F2464 / 322x GE RJ45 FortiLink
FortiGate 70G2496 / 482x GE RJ45 FortiLink
FortiGate 80F2496 / 482x GE RJ45 FortiLink; on the 80F-PoE the FortiLink ports supply PoE/PoE+
FortiGate 90G24128 / 64
FortiGate 100F32128 / 642x 10GE SFP+ FortiLink
FortiGate 120G48128 / 644x 10GE SFP+ FortiLink; 48 switches require FortiOS 7.6.1+, 32 on earlier versions
FortiGate 200F64256 / 1282x 10GE SFP+ FortiLink
FortiGate 400F96512 / 25696 switches require FortiOS 7.6.1+
FortiGate 600F1281,024 / 512FortiOS 7.6.1+
FortiGate 900G1962,048 / 1,024FortiOS 7.6.1+
FortiGate-VM (VM-08S and above)3004,096 / 1,024Virtual instance; performance depends on the host hardware

The values in the table are the maximum figures from the official data sheets; they are not design targets. In practice the FortiGate is simultaneously performing security inspection, VPN termination and SD-WAN routing, so rather than pushing the managed switch count to the ceiling you should leave headroom for growth. A FortiGate 100F is typically sufficient for a single-floor branch office, whereas a FortiGate 200F or above is preferred in a multi-building campus LAN. The FortiOS version is a separate constraint, but this condition does not apply to every model: in the 120G (48), 400F (96), 600F (128) and 900G (196) data sheets the upper limits in the table are given for FortiOS 7.6.1 and later — the 120G, for example, manages 32 rather than 48 switches on earlier versions. No such version condition is stated in the data sheets for the 60F, 70G, 80F, 90G, 100F, 200F and FortiGate-VM.

Another planning input is the speed of the FortiLink interface. On entry-level FortiGate models the FortiLink ports are 1 Gbit RJ45 interfaces; models such as the 100F, 120G and 200F have 10GE SFP+ FortiLink ports. In designs where all access layer traffic passes through the firewall, that difference can translate directly into a bottleneck at campus scale.

How is the PoE budget planned, and is PoE++ mandatory for Wi-Fi 7 access points?

PoE+ support is spread across the FortiSwitch family as a whole; selected models deliver 90 W per port with 802.3bt (PoE++). Fortinet uses the phrase "PoE+ support in all models" in both the Secure Access and Secure Campus data sheets (Fortinet FortiSwitch Secure Access data sheet, 2026); in practice, because every series includes separate non-PoE, half-PoE and full-PoE SKUs, power capacity is determined by the SKU you choose rather than by the model name. A concrete example on the 802.3bt side is the FS-124G-FPOE: it offers 8 x 802.3bt (90 W) and 16 x 802.3af/at (30 W) ports together. For flagship Wi-Fi 7 class access points, a 30 W port will not be enough in most scenarios.

Fortinet's Wi-Fi 7 flagship models FAP-441K and FAP-443K offer four radios and four spatial streams, support the 6 GHz band, and have 10 Gigabit Ethernet ports and 802.3bt PoE (Fortinet FortiAP Series data sheet, 2026). These two requirements arise together on the switch side: 802.3bt power and an access port faster than 1 Gbit. A design that looks only at the PoE budget and ignores port speed will not realize the return on the investment made on the wireless side. When FortiAP wireless network solutions and FortiSwitch are engineered together, these two items are evaluated in the same calculation.

PoE standardPort power stated in the data sheetTypical load
802.3af / 802.3at (PoE / PoE+)30 WIP phones, fixed IP cameras, access points powered in the 802.3at class, access control units
802.3bt (PoE++)90 WFlagship Wi-Fi 7 access points (FAP-441K, FAP-443K), pan-tilt-zoom (PTZ) cameras, high-power edge devices

The total PoE budget varies significantly by model and SKU, which is why it is impossible to give a single figure and say "this is the FortiSwitch PoE budget". Fortinet's data sheets include a separate PoE Power Budget row for each SKU, and in the non-PoE variant of the same series that value is zero. The table below shows examples verified against the PoE Power Budget rows in the Secure Access (Fortinet, 2026) and Secure Campus (Fortinet, 2026) data sheets.

Model (SKU)PoE portsTotal PoE budgetSwitching capacity (duplex)
FS-124F-FPOE24x 802.3af/at370 W128 Gbps
FS-148F-FPOE48x 802.3af/at740 W176 Gbps
FS-124G-FPOE8x 802.3bt (90 W) + 16x 802.3af/at (30 W)780 W240 Gbps
FS-548D-FPOE48x 802.3af/at750 W (single PSU) / 1,440 W (dual PSU)336 Gbps
FS-348G-FPOE48x 802.3bt type 4 (90 W)/at/af1,540 W248 Gbps
FS-648F-FPOE48x 802.3af/at/bt type 41,800 W720 Gbps
FS-T1024F-FPOE24x 802.3af/at/bt type 41,440 W880 Gbps

The values in the table are the maximum PoE output from the relevant SKU's data sheet; they do not mean that every port can be supplied with maximum power at the same time. In project design the budget should be derived by adding up three items: the instantaneous consumption of the access points, the IP phone and camera load, and the allowance set aside for IoT devices to be added later. The current official data sheet for the selected SKU must be re-confirmed on every project; the Fortinet portfolio is updated at SKU level.

A practical rule is to calculate the PoE budget from the actual device list rather than on the assumption that every port is occupied. If a 24-port floor cabinet is powering only a handful of access points and a group of IP phones, a mixed SKU that reserves the 802.3bt ports for the access points and leaves the remaining ports in the 30 W class — such as the FS-124G-FPOE — is a balanced choice in terms of both cost and power. A device in the FS-348G-FPOE class, where every port is 802.3bt, genuinely pays off only if there is a dense PTZ camera or Wi-Fi 7 rollout; otherwise you have paid for a budget you will never use.

Why should network segmentation be built at the switch layer?

Because the place an attack spreads is not the perimeter but the internal network. ENISA's 2025 Threat Landscape report examined 4,875 incidents between 1 July 2024 and 30 June 2025; phishing was the dominant intrusion vector at 60%, while exploitation of vulnerabilities accounted for 21.3% of initial access (ENISA Threat Landscape, 2025). In both vectors the attacker lands on a user device or an edge device at the first step. From that moment on, the size of the damage is determined by how wide the segment that device is connected to happens to be.

Verizon DBIR 2025 reports that the share of breaches involving a third party doubled from 15% to 30% in one year (Verizon DBIR, 2025). The maintenance company's laptop, an automation panel installed by a supplier, a temporary consultant account — all of them enter the corporate LAN through a switch port. Which VLAN that port lands in, which resources it can reach and whether it is automatically isolated when its behaviour changes determine whether the breach stays on one device or spreads across the whole network.

How does FortiSwitch apply this control?

In FortiLink mode, access control operates as an extension of FortiGate's policy engine. Device profiling classifies every device that is plugged in, IoT-class devices are automatically placed into defined segments, the relevant port is quarantined in the event of a policy violation, and virtual patching steps in for devices that cannot be patched (Fortinet, 2026). These four capabilities are defined in the data sheet as basic NAC functionality requiring no additional cost — meaning they do not create a separate NAC server, a separate console or a separate operational burden.

On the authentication side, FortiSwitch supports the port-based and MAC-based forms of 802.1X and the MAC Access Bypass (MAB) method as listed in the data sheet; dynamic VLAN assignment based on RADIUS attributes (RFC 4675), guest/fallback VLAN and RADIUS CoA are also among the supported capabilities (Fortinet, 2026). An important distinction here: the port security automation of FortiLink NAC does not require 802.1X. Organizations that cannot build an 802.1X infrastructure, or that are migrating in stages, can start with profile-based automatic segmentation and enable 802.1X later; the two mechanisms are complementary rather than alternatives.

Used together with detection and response capabilities on the endpoint side, the chain is complete: when FortiEDR detects suspicious behaviour on an endpoint, isolation of the switch port can be triggered through the Security Fabric. Response then happens at the network layer within seconds, instead of waiting for an engineer to walk to the floor cabinet and unplug a cable.

A common mistake in segmentation design is to treat increasing the number of VLANs as segmentation. What separates segments from one another is not the VLAN tag but the inspection of traffic between them. That is precisely where the value of positioning FortiSwitch alongside FortiGate lies: inter-segment traffic passes through the same policy and the same inspection set as perimeter traffic.

Which management modes does FortiSwitch run in, and which model should you choose?

FortiSwitch can be positioned in three management modes: FortiLink (through FortiGate), standalone and FortiEdge Cloud. The Secure Access series scales to 48 access ports in a 1 RU chassis and offers uplinks up to 10GE (Fortinet FortiSwitch Secure Access data sheet, 2026). The choice of mode depends largely on whether a FortiGate is present in the environment and where you want management to be consolidated.

Which mode suits which scenario?

FortiLink mode is the default choice if a FortiGate is already present; policy and network configuration are consolidated in one place and the free NAC capabilities come into play in this mode. Standalone mode offers classic switch management in environments where there is no FortiGate or where the switch sits behind another firewall. FortiEdge Cloud is for scenarios where per-device on-site management is not feasible and a large number of small locations need to be managed from a single pane in the cloud; in retail and dealer networks with many branches, this model reduces the operational load significantly.

In distributed organizations with a large number of FortiGates, management can be moved up a layer. Fortinet states that FortiManager supports 100,000 Fortinet devices including FortiGate, FortiSwitch, FortiAP, SD-WAN and FortiSASE (Fortinet FortiManager product page, 2026). In designs where branch security is moved to the cloud, a local LAN layer engineered together with FortiSASE brings remote users and in-office users together under the same policy set.

How are port density and uplink determined?

There are three inputs to access layer sizing: the number of ports per user, the list of devices to be powered over PoE, and uplink capacity. A 1 RU chassis with 48 access ports provides sufficient density for a typical floor cabinet; in smaller floor or room distributions, models with fewer ports reduce cabling cost. On the uplink side, the 10GE option offered by the Secure Access series ensures that the link from the floor cabinet to the distribution layer can carry the total capacity of the access ports; feeding a 48-port switch with a single 1GE uplink creates a bottleneck in busy office environments. At campus scale the ceiling is higher: the FortiSwitch Secure Campus series offers uplinks up to 100GE and stacking of up to 300 switches per FortiGate (Fortinet FortiSwitch Secure Campus data sheet, 2026). The FS-T1024F-FPOE, for example, combines 24 x 10GBASE-T access ports with 2x 40GE/100GE QSFP28 uplinks; the FS-648F-FPOE offers 8x 25GE SFP28 uplinks. This is why the generalization "the FortiSwitch uplink is 10GE" is wrong — the 10GE limit belongs to the access-oriented Secure Access series.

In floor cabinets that require redundancy, taking two uplinks to the distribution layer over independent paths prevents a single cable or transceiver failure from causing an outage across the whole floor. Although this design decision adds the cost of a few extra optical modules to the initial investment, it pays for itself quickly compared with the cost of operational downtime. A similar balance exists on the power side, and the direct relationship between redundancy and capacity is often overlooked: the total PoE budget of the FS-548D-FPOE is 750 W with a single power supply and 1,440 W with dual power supplies (Fortinet, 2026). In other words, the second PSU buys not only fault tolerance but also usable PoE budget; on PoE-dense floors, a design calculated with a single PSU can hit the budget limit at go-live.

Which KVKK and PCI DSS obligations does the switch layer address?

Network segmentation and access logging are controls named directly in both the KVKK technical measures and the PCI DSS v4.0 requirements. The January 2018 publication titled Personal Data Security Guide (Technical and Administrative Measures) from KVKK (Turkey's data protection law) defines the firewall and gateway as a priority measure and the first line of defence in protecting systems containing personal data; in the guide's summary table of technical measures, network security, access logs, log records and intrusion detection/prevention systems are listed as separate items (KVKK Personal Data Security Guide, 2018).

On the PCI DSS v4.0 side, the terminology has changed: the standard now uses Network Security Control (NSC) instead of "firewall". For organizations that process card data, the requirements that directly concern the switch layer are as follows (PCI DSS v4.0 SAQ D for Merchants):

  • 1.4.1 — NSCs are implemented between trusted and untrusted networks.
  • 1.3.3 — An NSC is installed between the wireless network and the cardholder data environment (CDE); all traffic from the wireless network to the CDE is denied by default.
  • 1.2.7 — NSC configurations are reviewed at least once every six months.
  • 11.4.5 — If segmentation is used to isolate the CDE from other networks, segmentation controls are penetration tested at least once a year and after every segmentation change (PCI SSC Scoping and Segmentation Guidance).

In practice these requirements ask for two things: that the segment really is separated, and that this can be proven. The proof side looks to the logging and reporting layer. The FortiAnalyzer hardware family scales to a daily log capacity of between 100 GB and 8,300 GB, supports between 180 and 10,000 devices/VDOMs, and offers ready-made compliance reports such as PCI-DSS and HIPAA (Fortinet FortiAnalyzer data sheet, 2026). During an audit it is not enough to say "segmentation was in place"; which device sat in which segment and how inter-segment traffic was inspected must be demonstrable from the records.

In financial institutions subject to BDDK (Turkish banking regulator) supervision and in public sector organizations, local support, Turkish documentation and spare parts availability also enter the evaluation criteria. As a Fortinet authorized channel partner, Sora Yazılım defines these items within the contract scope; RMA processes and on-site intervention terms are clarified at the quotation stage.

How is migration from an existing switch infrastructure to FortiSwitch planned?

Migration is not an operation in which every switch is replaced over a single weekend; it is a phased project that advances floor by floor. The sequence we apply is generally as follows: documenting the current topology and VLAN plan, collecting the PoE device inventory, defining the target segmentation model on FortiGate, bringing a pilot floor into service with FortiLink, and after validation, moving the remaining floors one by one.

The inventory stage is where most projects produce the biggest surprises. Unregistered switches in floor cabinets, undocumented VLANs, legacy IP phone exchange links still in production and IoT devices with no known owner typically come to light at this point. That is why we treat the inventory not as pre-work before the migration but as the migration's first deliverable; a segmentation model can only be built on an accurate inventory.

In selecting the pilot floor we prioritize two criteria: that the user density is representative, and that no critical business process sits on that floor. The post-pilot validation list includes working 802.1X authentication, prioritization of voice traffic, PoE devices coming back up cleanly after a restart, and testing failover over the backup uplink.

A single-vendor LAN target may not be the right choice in every environment. In projects where budget constraints are decisive, or where raw port density matters more than security integration, Ruijie network solutions are evaluated as an alternative. Our decision criterion is clear: if a FortiGate-centred security architecture is being built and policy consistency is required at the access layer, the return on FortiSwitch is high; otherwise a more cost-effective switch family may be sufficient.

In projects where the network design has to be addressed together with the virtualization, container and automation layers, our DevOps and infrastructure services step in; VLAN and segment design, application placement and access policies are combined into a single architecture exercise.

Let's work out together how many switches with how many ports you need on the FortiSwitch side, how your PoE budget looks against the real device list, and how many switches your existing FortiGate can manage. Share your current topology and device inventory, and let us prepare a design document and quotation covering the segmentation model, model recommendation and migration plan. Reach us through our contact page to review licensing, deployment, migration and managed service options with us as a Fortinet authorized channel partner.

Key features

What it offers

  • Single-pane management from the FortiGate interface via FortiLink; no separate switch console required
  • Management of 8–300 switches from one place, depending on the FortiGate model
  • Basic NAC at no extra cost: device profiling, automatic IoT segmentation, quarantine, virtual patching
  • Up to 48 access ports in a 1 RU chassis (Secure Access and Secure Campus series)
  • Uplink: up to 10GE in the Secure Access series, up to 100GE in the Secure Campus series
  • PoE+ support across the family; non-PoE, half-PoE and full-PoE SKU options
  • 90 W per port with 802.3bt on selected models (FS-124G-FPOE: 8x 90 W + 16x 30 W, 780 W total)
  • Total PoE budget from 370 W to 1,800 W depending on SKU; on some models a dual PSU raises the budget
  • Three management modes: FortiLink, standalone and FortiEdge Cloud
  • Port-level access control with 802.1X (port-based / MAC-based / MAB); dynamic VLAN assignment via RADIUS
  • Security Fabric integration: automatic isolation of the switch port on an endpoint event
  • Central logging, compliance reporting and audit evidence with FortiAnalyzer
  • Large-scale, multi-site management with FortiManager
  • 802.3bt power and high-speed access port planning for Wi-Fi 7 access points
Tech Summary

Important technical data

Management modes
FortiLink (through FortiGate), standalone, FortiEdge Cloud
Managed switches per FortiGate
8 – 300 (depending on the FortiGate model)
Access port density
Up to 48 access ports in a 1 RU chassis in the Secure Access and Secure Campus series
Uplink
Up to 10GE in the Secure Access series; up to 100GE in the Secure Campus series
PoE support
PoE+ support is offered across the family (every series has non-PoE, half-PoE and full-PoE SKUs); selected models deliver 90 W per port with 802.3bt
Example PoE port distribution
FS-124G-FPOE: 8x 802.3bt (90 W) + 16x 802.3af/at (30 W), 780 W total PoE budget
Example total PoE budgets
FS-124F-FPOE 370 W · FS-148F-FPOE 740 W · FS-124G-FPOE 780 W · FS-548D-FPOE 750/1,440 W (single/dual PSU) · FS-348G-FPOE 1,540 W · FS-648F-FPOE 1,800 W · FS-T1024F-FPOE 1,440 W
Port authentication
802.1X port-based and MAC-based, MAC Access Bypass (MAB), dynamic VLAN assignment (RFC 4675), RADIUS CoA
NAC
Basic NAC at no extra cost with FortiLink: profiling, IoT segmentation, quarantine, virtual patching
FortiOS requirement
The 120G (48), 400F (96), 600F (128) and 900G (196) upper limits are for FortiOS 7.6.1 and above; no version condition is stated in the data sheets of the other models
Central management scale
FortiManager supports 100,000 Fortinet devices (FortiGate, FortiSwitch, FortiAP, SD-WAN, FortiSASE)
Supply and support in Turkey
Sora Yazılım — Fortinet authorized channel partner; licensing, deployment, migration, managed service
Use Cases

When would you choose this product?

Corporate office

New office LAN and WLAN deployment

FortiGate + FortiSwitch + FortiAP are positioned together so that wired and wireless access are consolidated into a single policy set; VLANs, PoE and access rules are managed from the FortiGate interface, and no separate switch management process arises after deployment.

Manufacturing / OT

Separating the production network from the corporate network

PLCs, HMIs and field sensors are recognized through device profiling and placed into separate segments; virtual patching is enabled for legacy control devices that cannot be updated, and inter-segment traffic is inspected by FortiGate policies.

Retail / Branch network

Multi-site store network

In branches with no on-site technical staff, switches are managed centrally with FortiLink or FortiEdge Cloud; point-of-sale and payment terminals are kept on a segment separate from guest Wi-Fi, aligning with PCI DSS segmentation requirements.

Education

Campus access layer

Students, academic staff, administrative units and laboratory devices are separated into different segments; port-level authentication is applied with 802.1X and the access points in floor cabinets are powered from 802.3bt-capable ports.

Healthcare

Separating medical devices from the clinical network

End-of-life medical devices that remain in production are kept in isolated segments and the port is automatically quarantined in the event of a behavioural violation; records of traffic carrying personal health data are kept on FortiAnalyzer, documenting KVKK technical measure requirements.

Who is it for?

IT and network teams in branch, campus and multi-site organizations that want to manage the access layer under the same policy set as FortiGate; organizations with PoE-powered wireless, IP telephony and IoT infrastructure; and organizations with segmentation and logging obligations under KVKK, PCI DSS or BDDK.

Frequently Asked Questions

Frequently asked questions

What is the difference between FortiLink mode and standalone mode?
In FortiLink mode the switch is under FortiGate's control; VLANs, port configuration, PoE and access policies are managed from the FortiGate interface, and the basic NAC capabilities that require no extra cost come into play. In standalone mode the switch is configured from its own interface like a classic managed switch. Standalone mode is preferred if there is no FortiGate in the environment or if the switch sits behind another firewall. The third option, FortiEdge Cloud, is for scenarios where a large number of small locations are managed from the cloud.
How many FortiSwitches can one FortiGate manage?
It varies between 8 and 300 depending on the FortiGate model (Fortinet FortiSwitch Secure Access data sheet, 2026). Verified examples: FortiGate 60F, 70G, 80F and 90G 24; 100F 32; 120G 48; 200F 64; 400F 96; 600F 128; 900G 196; FortiGate-VM (VM-08S and above) 300. Of these values, those for the 120G, 400F, 600F and 900G are given in the data sheets for FortiOS 7.6.1 and later — on earlier versions the 120G manages 32 switches. The data sheets of the other models state no version condition. These figures are upper limits; headroom for growth should be left in the design.
Is PoE++ mandatory for Wi-Fi 7 access points?
Fortinet's Wi-Fi 7 flagship models FAP-441K and FAP-443K have 10 Gigabit Ethernet ports and 802.3bt PoE (Fortinet FortiAP Series data sheet, 2026); a 30 W port is not sufficient for these models. On the FortiSwitch side, PoE+ support exists across the family, while 90 W per port with 802.3bt is offered on selected models. Across the FortiAP portfolio as a whole the PoE requirement is 802.3at or 802.3bt depending on the model; for that reason the PoE class in each access point model's data sheet must be checked separately.
Does FortiSwitch remove the need to buy a separate NAC product?
The FortiLink integration brings four capabilities that the data sheet defines as basic NAC functionality requiring no additional cost: device profiling, automatic segmentation for IoT, quarantine on violation and virtual patching (Fortinet, 2026). This set is sufficient for most mid-sized organizations. In scenarios that require a complex guest portal, certificate-based onboarding flows or multi-source posture assessment, an additional identity/NAC component comes into play; we determine the requirement together during project analysis.
How large should the total PoE budget be?
There is no single figure: the total PoE budget depends on the SKU and is given separately for each SKU in the Fortinet data sheets. Verified examples: FS-124F-FPOE 370 W, FS-148F-FPOE 740 W, FS-124G-FPOE 780 W, FS-348G-FPOE 1,540 W, FS-648F-FPOE 1,800 W, FS-T1024F-FPOE 1,440 W; on the FS-548D-FPOE the budget is 750 W with a single power supply and 1,440 W with dual power supplies. The correct method is to confirm the budget in the current data sheet of the selected SKU and to total the consumption of access points, IP phones, cameras and IoT devices to be added later from the real device list.
How is 802.1X authentication set up?
The FortiSwitch data sheet lists the port-based and MAC-based forms of 802.1X, MAC Access Bypass (MAB), dynamic VLAN assignment (RFC 4675), guest/fallback VLAN and RADIUS CoA as supported capabilities. FortiAuthenticator or the organization's existing RADIUS/NPS infrastructure can be used as the identity source. The port security automation of FortiLink NAC does not require 802.1X; for that reason we recommend a phased migration: running first in monitoring mode to detect devices outside the inventory, then switching to enforcement mode, reduces the risk of outages significantly.
How long does migration from an existing Cisco or HPE switch infrastructure take?
The duration depends on the number of floor cabinets and on how well the inventory is documented. In our own project experience, the decisive item is not the switch replacement but the inventory and segmentation design; we therefore plan the project in four phases: inventory, target model design, pilot floor and phased migration. The output of each phase is delivered in writing, and the rollback plan is defined in advance.
How does FortiSwitch contribute to PCI DSS and KVKK compliance?
PCI DSS v4.0 requires NSCs to be implemented between trusted and untrusted networks (1.4.1), traffic from the wireless network to the cardholder data environment to be denied by default (1.3.3), NSC configurations to be reviewed at least once every six months (1.2.7) and segmentation controls to be penetration tested at least once a year (11.4.5). The KVKK Personal Data Security Guide of January 2018 lists network security, access logs and log records among the technical measures. FortiSwitch provides segmentation and access control, while FortiAnalyzer provides the records and reporting that serve as evidence.
Is a single 48-port switch or two 24-port switches the better choice?
The Secure Access and Secure Campus series scale to 48 access ports in a 1 RU chassis. A single 48-port device is more efficient in terms of cabinet space and management; however, a single device failure means an outage across the whole floor. The PoE budget also enters the decision: the FS-124F-FPOE offers 370 W while the FS-148F-FPOE offers 740 W, so when the port count doubles the budget doubles as well. On floors with low outage tolerance, splitting across two devices and taking the uplinks over independent paths is safer; the decision is driven by the number of users per floor and business continuity requirements.
Can I get pricing information?
Because the model, port density, PoE class, uplink type and support level vary from project to project, we do not publish prices on this page. If you share your device inventory and floor plan, we will prepare a quotation covering the model recommendation, PoE calculation and support scope; you can reach us through the our contact page page.
Vendor's official product page

Opens the vendor's original technical documentation and product page in a new tab.

FortinetFortiSwitch
Related Services

Services we deliver alongside this product

FortiSwitch licensing + deployment + support

Sora Yazılım handles licensing, deployment, training and ongoing management — all from a single team.

WhatsApp Support