Overview
To map FortiSwitches managed through FortiLink, Domotz needs three things: SNMP access to the FortiGate, a routable path from the Collector to the FortiLink network, and SSH access to each FortiSwitch.
The FortiGate acts as the FortiLink controller, so SNMP on the FortiGate lets Domotz discover the managed switches. SSH on each switch lets Domotz read the interface tables and identify which client devices are connected to which port. FortiAPs are not mapped through this method.
| Requirement | Where | Why Domotz needs it |
|---|---|---|
| SNMP enabled | FortiGate firewall/controller | Discover FortiLink-managed switches |
| Routable FortiLink network | FortiGate routing and firewall policies | The Collector must reach every FortiSwitch from its current network |
| SSH enabled | Every FortiLinked FortiSwitch | Extract interfaces and the devices connected to them |
Before you start: you need admin access to the FortiGate (GUI and CLI) and the IP address of the Domotz Collector.
Step 1: Enable SNMP on the FortiGate
SNMP must be enabled on the FortiGate interface the Collector reaches, with the Collector’s IP allowed as an SNMP host. Follow How to configure SNMP on a FortiGate, then come back here for Step 2.
Step 2: Make the FortiLink network reachable from the Collector
Start by checking the subnet currently assigned to the FortiLink interface. The default depends on the FortiGate model and firmware: some use a non-routable APIPA block (169.254.1.1/24), while many already use a routable block such as 10.255.1.0/24. If the Collector can already reach the switches, skip to sub-step 2 (Fortinet: Configuring the FortiLink interface).
Warning: changing FortiLink addressing on a production network can disconnect the managed switches, and FortiLink does not always come back up cleanly. Only make this change during a planned maintenance window, with a configuration backup and console access to the switches. The exact procedure varies across FortiGate and FortiSwitch models and firmware versions, so check Fortinet’s documentation for yours.
1. Assign the switches a routable management address (only if needed)
The steps to change FortiLink addressing vary by FortiGate and FortiSwitch model and firmware, so follow Fortinet’s documentation for your version:
- Configuring FortiLink (FortiSwitch FortiLink Guide; use the version selector to match your firmware)
- Technical Tip: How to modify FortiLink FortiSwitch IP Addresses Without Traffic Interruption
2. Allow PING and SSH from the Collector
Create a firewall policy from the Collector’s interface to the fortilink interface allowing PING and SSH. SNMP is not needed on the switches; it is only required on the FortiGate controller (Step 1). If the Collector sits behind another router, add a static route to the new FortiLink subnet pointing to the FortiGate.
Limit the policy source to the Collector’s IP only. Fortinet’s design keeps direct access to managed switches as restricted as possible, so avoid opening SSH to the switches from any other source.
config firewall policy
edit 0
set name "Domotz-to-FortiLink"
set srcintf "<collector_interface>"
set dstintf "fortilink"
set srcaddr "<collector_address_object>"
set dstaddr "all"
set action accept
set schedule "always"
set service "PING" "SSH"
set nat disable
next
end
You do not need to add the FortiLink subnet as a Routed Network in Domotz. Once the Collector discovers the FortiLink devices through the SNMP scan of the FortiGate, it adds that network automatically.
Verify reachability
From the FortiGate CLI, list the managed switches and their IPs:
execute switch-controller get-conn-status
Then confirm in Domotz that each FortiSwitch appears in the device list and shows as online.
Step 3: Enable SSH on every FortiSwitch
SSH must be allowed on each FortiLinked switch, with a known admin password, so Domotz can read the interfaces and the devices connected to them.
On the FortiGate, set a common admin password for all managed switches through the switch profile:
config switch-controller switch-profile
edit "default"
set login-passwd-override enable
set login-passwd <switch_admin_password>
next
end
Then make sure SSH is allowed on each switch’s management interface.
Step 4: Add credentials in Domotz and verify the mapping
Once the network side is ready, give Domotz the same credentials you configured above.
- Open the FortiGate device in Domotz and enter the SNMP community (or SNMPv3 user) from Step 1.
- Open each FortiSwitch and enter the SSH username (
admin) and password from Step 3. - Wait for the next discovery cycle (allow up to 30 minutes).
- Open the Network Topology map and confirm the FortiSwitches appear under the FortiGate, with client devices linked to their ports.
Tip: setting the password once in the FortiGate switch profile (Step 3) keeps the Domotz credentials identical across all switches.
Troubleshooting
| Symptom | Likely cause | What to check |
|---|---|---|
| No FortiSwitches discovered | SNMP not reaching the FortiGate | SNMP enabled on the right interface, Collector IP listed under the community hosts, correct community in Domotz |
| FortiSwitches missing or offline | Switches still on APIPA (169.254.x.x) addresses | Proper IP and mask assigned to each switch, PING and SSH allowed from the Collector, static route on any upstream router |
| Switches shown, but no connected devices on their ports | SSH blocked or wrong password | allowaccess includes ssh, profile password pushed, credentials in Domotz match |
| SSH works from the FortiGate but not from the Collector | Policy missing the SSH service | Add SSH to the firewall policy in Step 2 |
Still stuck? Contact Domotz Support (support@domotz.com) with your Collector name and the FortiGate model and firmware version.