FortiSwitch
FortiSwitch: Ethernet switches with Security Fabric. FortiGate managed, 802.1X/NAC, PoE++, Zero-Touch Provisioning, stacking.

Key Features
- Security Fabric native integration
- FortiGate management (FortiLink)
- 802.1X and FortiNAC integration
- PoE/PoE+/PoE++ up to 90W
- Virtual stacking and MCLAG
Table of Contents
Why do you need FortiSwitch?
73% of attacks exploit lateral movement in LAN. Traditional switches are commodity - they pass traffic without security inspection. Separate management for switching and security creates silos and visibility gaps.
FortiSwitch is Ethernet switches with native Security Fabric integration. Managed directly by FortiGate, they implement security policies at port level. Zero additional licenses for basic switching and security features.
How does it work?
FortiLink Integration
FortiGate as controller:
- Automatic switch discovery
- Centralized configuration from FortiGate
- Security policy enforcement on ports
- Unified management interface
- Firmware management
Security Fabric Visibility
Full network visibility:
- Device identification per port
- Traffic inspection through FortiGate
- IOC correlation
- Anomaly detection
- Quarantine capability
Zero-Touch Provisioning
Simplified deployment:
- Switch connected to network
- Automatic registration with FortiGate
- Configuration push
- Ready to work in minutes
- FortiCloud optional
Key Features
Network Access Control
- 802.1X authentication
- MAC authentication bypass
- Guest VLAN
- FortiNAC integration
- Dynamic VLAN assignment
Segmentation
- VLAN isolation
- Private VLAN
- Microsegmentation with FortiGate
- Traffic quarantine
- East-west control
High Availability
- FortiLink stacking
- Multi-Chassis LAG (MCLAG)
- STP/RSTP/MSTP
- Hitless failover
- Single IP management
Power over Ethernet
- 802.3af PoE (15.4W)
- 802.3at PoE+ (30W)
- 802.3bt PoE++ (60W/90W)
- Power budgeting
- Per-port management
FortiSwitch Portfolio
Access Layer:
| Series | Ports | PoE | Use Case |
|---|---|---|---|
| 108F | 8x GE | PoE+ | Small office |
| 124F | 24x GE | PoE+ | Branch |
| 148F | 48x GE | PoE+ | Campus |
| 248E | 48x GE + 4x 10G | PoE+ | Enterprise |
Distribution/Aggregation:
- 424E/448E - 24/48 GE + 10G uplinks
- 524D/548D - 10G switches
Data Center:
- 1024E/1048E - 10G + 40G
- 3032E - 40G/100G spine
Who is it for?
- Organizations with FortiGate seeking unified network + security
- Enterprises needing microsegmentation
- Companies deploying Wi-Fi 6E/7 with PoE++
- IT teams wanting simplified management
Benefits
For IT: Single pane of glass with FortiGate, ZTP deployment, no extra licenses
For security: Security policy enforcement, traffic visibility, NAC integration
For business: Reduced OpEx, faster deployment, unified vendor
Specifications
| Management | FortiGate (FortiLink), standalone |
| PoE | Up to PoE++ (90W) |
| Stacking | Virtual stacking, MCLAG |
| Security | 802.1X, FortiNAC, VLAN |
FAQ
Does FortiSwitch require separate controller? No. FortiGate manages FortiSwitch through FortiLink without additional software.
Which models have PoE++? F-series with PoE++ (802.3bt) up to 90W per port for demanding devices.
How does FortiLink work? Proprietary protocol connecting FortiGate with FortiSwitch. Automatic discovery, centralized config, policy push.
Can I use it without FortiGate? Yes. Standalone mode with CLI/GUI/SNMP. But you lose Security Fabric benefits.
How does stacking work? Virtual stacking through FortiLink. MCLAG for physical redundancy without dedicated stacking cables.
How many switches can FortiGate manage? Depending on FortiGate model - from dozens to hundreds of switches.
Does FortiSwitch integrate with FortiNAC? Yes. Dynamic VLAN assignment, MAC auth bypass, device profiling, quarantine.
What uplinks in access models? Typically 4x SFP+ (10G) in 24/48 port models for aggregation.
Are outdoor/industrial models available? Yes. Rugged series for harsh environments.
How does support work? Fortinet 24/7 TAC. nFlo as partner offers network design and switching deployment.
Inquire about FortiSwitch
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Comprehensive Network Infrastructure Implementation
IT Infrastructure
Build a network that doesn't fail. From design through implementation to 24/7 support.
Firewall and NGFW Implementation
Cybersecurity
Effective network protection against threats. Implementation and configuration in 2 weeks.
IT Infrastructure Management Automation
IT Infrastructure
Save 500+ hours per year by eliminating manual tasks. Ansible, Terraform, PowerShell.
Backup and Disaster Recovery
IT Infrastructure
Recover data in minutes, not days. Backup and DR with tested RTO/RPO.
From Our Knowledge Base
Articles related to this solution
CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection')...
Security Alert - CVE-2026-25089 (Fortinet Fortisandbox). CVSS: 9.8 (critical).
CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Security Alert - CVE-2026-0257 (Palo Alto Networks PAN-OS). CVSS: 9.1 (critical). EPSS: 36%.
CVE-2026-38702: Command injection in InHand Networks IR302
Security Alert - CVE-2026-38702 (InHand Networks IR302). CVSS: 9.8 (critical).
Related Products
Other solutions you might be interested in
Aruba Access Points
Aruba Networks
Aruba Access Points: Wi-Fi 6/6E/7 access points with AI-driven RF and Zero Trust. Up to 28.8 Gbps, IoT-ready.
Aruba AirWave
Aruba Networks
Aruba AirWave: on-premises multi-vendor network management. Monitoring, configuration, compliance for existing deployments.
Aruba Central
Aruba Networks
Aruba Central: cloud-native network management with AIOps. Single dashboard for Wi-Fi, switching, SD-WAN. Zero Touch Provisioning.
Aruba CX Switches
Aruba Networks
Aruba CX Switches: next-generation switches with AOS-CX. REST API, Network Analytics Engine, VSX for HA without STP.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist