Domotz
Integrations

How to Map FortiLink Devices in Domotz

By Henrique Salvador Updated 9 Oct 2026 5 min read
On this page
3 min

Overview

To map FortiSwitches managed through FortiLink, Domotz needs three things: SNMP access to the FortiGate, a routable path from the Collector to the FortiLink network, and SSH access to each FortiSwitch.

The FortiGate acts as the FortiLink controller, so SNMP on the FortiGate lets Domotz discover the managed switches. SSH on each switch lets Domotz read the interface tables and identify which client devices are connected to which port. FortiAPs are not mapped through this method.

RequirementWhereWhy Domotz needs it
SNMP enabledFortiGate firewall/controllerDiscover FortiLink-managed switches
Routable FortiLink networkFortiGate routing and firewall policiesThe Collector must reach every FortiSwitch from its current network
SSH enabledEvery FortiLinked FortiSwitchExtract interfaces and the devices connected to them

Before you start: you need admin access to the FortiGate (GUI and CLI) and the IP address of the Domotz Collector.

Step 1: Enable SNMP on the FortiGate

SNMP must be enabled on the FortiGate interface the Collector reaches, with the Collector’s IP allowed as an SNMP host. Follow How to configure SNMP on a FortiGate, then come back here for Step 2.

Step 2: Make the FortiLink network reachable from the Collector

Start by checking the subnet currently assigned to the FortiLink interface. The default depends on the FortiGate model and firmware: some use a non-routable APIPA block (169.254.1.1/24), while many already use a routable block such as 10.255.1.0/24. If the Collector can already reach the switches, skip to sub-step 2 (Fortinet: Configuring the FortiLink interface).

Warning: changing FortiLink addressing on a production network can disconnect the managed switches, and FortiLink does not always come back up cleanly. Only make this change during a planned maintenance window, with a configuration backup and console access to the switches. The exact procedure varies across FortiGate and FortiSwitch models and firmware versions, so check Fortinet’s documentation for yours.

1. Assign the switches a routable management address (only if needed)

The steps to change FortiLink addressing vary by FortiGate and FortiSwitch model and firmware, so follow Fortinet’s documentation for your version:

2. Allow PING and SSH from the Collector

Create a firewall policy from the Collector’s interface to the fortilink interface allowing PING and SSH. SNMP is not needed on the switches; it is only required on the FortiGate controller (Step 1). If the Collector sits behind another router, add a static route to the new FortiLink subnet pointing to the FortiGate.

Limit the policy source to the Collector’s IP only. Fortinet’s design keeps direct access to managed switches as restricted as possible, so avoid opening SSH to the switches from any other source.

config firewall policy
    edit 0
        set name "Domotz-to-FortiLink"
        set srcintf "<collector_interface>"
        set dstintf "fortilink"
        set srcaddr "<collector_address_object>"
        set dstaddr "all"
        set action accept
        set schedule "always"
        set service "PING" "SSH"
        set nat disable
    next
end

You do not need to add the FortiLink subnet as a Routed Network in Domotz. Once the Collector discovers the FortiLink devices through the SNMP scan of the FortiGate, it adds that network automatically.

Verify reachability

From the FortiGate CLI, list the managed switches and their IPs:

execute switch-controller get-conn-status

Then confirm in Domotz that each FortiSwitch appears in the device list and shows as online.

Step 3: Enable SSH on every FortiSwitch

SSH must be allowed on each FortiLinked switch, with a known admin password, so Domotz can read the interfaces and the devices connected to them.

On the FortiGate, set a common admin password for all managed switches through the switch profile:

config switch-controller switch-profile
    edit "default"
        set login-passwd-override enable
        set login-passwd <switch_admin_password>
    next
end

Then make sure SSH is allowed on each switch’s management interface.

Step 4: Add credentials in Domotz and verify the mapping

Once the network side is ready, give Domotz the same credentials you configured above.

  1. Open the FortiGate device in Domotz and enter the SNMP community (or SNMPv3 user) from Step 1.
  2. Open each FortiSwitch and enter the SSH username (admin) and password from Step 3.
  3. Wait for the next discovery cycle (allow up to 30 minutes).
  4. Open the Network Topology map and confirm the FortiSwitches appear under the FortiGate, with client devices linked to their ports.

Tip: setting the password once in the FortiGate switch profile (Step 3) keeps the Domotz credentials identical across all switches.

Troubleshooting

SymptomLikely causeWhat to check
No FortiSwitches discoveredSNMP not reaching the FortiGateSNMP enabled on the right interface, Collector IP listed under the community hosts, correct community in Domotz
FortiSwitches missing or offlineSwitches still on APIPA (169.254.x.x) addressesProper IP and mask assigned to each switch, PING and SSH allowed from the Collector, static route on any upstream router
Switches shown, but no connected devices on their portsSSH blocked or wrong passwordallowaccess includes ssh, profile password pushed, credentials in Domotz match
SSH works from the FortiGate but not from the CollectorPolicy missing the SSH serviceAdd SSH to the firewall policy in Step 2

Still stuck? Contact Domotz Support (support@domotz.com) with your Collector name and the FortiGate model and firmware version.