Courseiva
Advanced Networking and SD-WANeasyMultiple ChoiceObjective-mapped

What Are the Prerequisites for FortiLink to Function?

A FortiGate is connected to a FortiSwitch via a trunk port. The administrator wants to manage the FortiSwitch using FortiLink. Which of the following is a prerequisite for FortiLink to function?

Quick Answer

The correct answer is that a dedicated FortiLink interface, either physical or VLAN, must be configured on the FortiGate. This is the foundational prerequisite for FortiLink to function because FortiLink creates a dedicated management channel between the FortiGate and the FortiSwitch, using a specific interface to carry both control traffic and native VLAN tagging for switch management. On the Fortinet NSE 7 Advanced Security NSE7 exam, this concept tests your understanding of how FortiSwitch is discovered and managed through FortiLink, often appearing as a trap where candidates assume DHCP or a separate management IP is required. Remember, the FortiGate itself acts as the DHCP server for FortiSwitch, so no external DHCP is needed, and the switch can share the FortiGate’s management IP. A simple memory tip: think of FortiLink as a dedicated “phone line” between the two devices—it must be a single, exclusive interface, not a shared trunk.

⚠ Common exam trap

Watch out — candidates often confuse FortiLink with CAPWAP (Option A) because both involve centralized management, but FortiLink is a layer-2 Ethernet-based protocol specific to FortiSwitch, not a wireless control protocol.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A dedicated FortiLink interface (physical or VLAN) must be configured on the FortiGate

FortiLink requires a dedicated interface on the FortiGate, either a physical port or a VLAN sub-interface, to establish the proprietary control and management channel with the FortiSwitch. This interface is automatically configured with the necessary FortiLink settings, including an internal management IP range and DHCP server, to discover and manage the switch. Without this dedicated interface, the FortiGate cannot initiate the FortiLink adjacency.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

One of 940 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on NSE7

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator wants to deploy FortiSwitch and FortiAP using LAN edge management from a FortiGate. Which TWO conditions must be met? (Choose two.)

medium
  • A.The FortiSwitch and FortiAP must be factory reset before connecting.
  • B.The FortiGate must be configured with the FortiLink interface for FortiSwitch and a CAPWAP interface for FortiAP.
  • C.The FortiSwitch and FortiAP must be in the same broadcast domain as the FortiGate management interface.
  • D.The FortiGate must have a valid FortiCare contract for unified management.
  • E.The FortiGate must have the 'set allowaccess' command enabled for HTTPS or SSH on the managing interface.

Why B: FortiGate uses a dedicated FortiLink interface (typically a hardware switch or aggregate interface) to manage FortiSwitch devices via L2 protocols, and a CAPWAP interface (a loopback or IP interface) to terminate CAPWAP tunnels from FortiAPs. These are the required interface types for LAN edge management, as specified in the FortiOS LAN edge deployment guide.

Variation 2. An administrator deploys a FortiGate in a remote office with a FortiSwitch and FortiAP. The LAN edge management features are used to manage these devices. The FortiGate is configured as a controller. Which three steps are required to manage the FortiAP via the FortiGate? (Choose THREE.)

hard
  • A.Configure DHCP option 138 or DNS to point FortiAP to FortiGate
  • B.Authorize the FortiAP by serial number on the FortiGate
  • C.Enable CAPWAP on the FortiGate
  • D.Enable LLDP on the FortiSwitch
  • E.Configure an SSID under the FortiAP profile

Why A: FortiAPs use DHCP option 138 or DNS to discover the FortiGate controller. DHCP option 138 provides the IP address of the FortiGate, while DNS resolves a predefined hostname (e.g., 'fortigate' or 'fg') to the controller's IP. Without this discovery mechanism, the FortiAP cannot locate the FortiGate to establish CAPWAP control and data tunnels.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.