FortiSwitch Specialist Practice Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/30

flashcard set

Earn XP

Description and Tags

Comprehensive vocabulary flashcards focused on FortiSwitchOS functions, including DHCP security, VLAN management, routing mechanisms, and FortiLink protocols.

Last updated 7:37 PM on 8/9/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

31 Terms

1
New cards

switch-controller-dhcp-snooping-verify-mac

A feature that verifies the destination MAC address match the learned MAC addresses in DHCP packets to protect against DHCP exhaustion attacks.

2
New cards

DHCP Option 82

Information used for agent information (Circuit ID and Remote ID) to assist in policy and billing; configuration is only available via the Command Line Interface (CLI).

3
New cards

Quarantine VLAN

A specific VLAN used to isolate devices that do not meet network security criteria, such as those failing 802.1X802.1X authentication.

4
New cards

DHCP Snooping Trust Model

Enforces a model where ports facing legitimate DHCP servers must be marked 'trusted' and edge ports marked 'untrusted' to prevent rogue DHCP server messages.

5
New cards

SNMP v2c Requirements

Requires activating the SNMP agent on the FortiSwitch and configuring community strings which function as passwords for authentication.

6
New cards

FortiLink Interface

A dedicated interface required on a FortiGate to manage communication, control, and policy enforcement for a connected FortiSwitch stack.

7
New cards

Native VLAN

The default internal ID assigned to any untagged frames arriving at a switch port; only one can be assigned per port.

8
New cards

Allowed-VLANs List

A configuration on a port that filters ingress and egress tagged frames; if a VLAN ID is not on this list, the switch drops the tagged frame.

9
New cards

Untagged VLAN List

A list that specifies VLANs for which the port will transmit egress frames without the 802.1Q802.1Q tag.

10
New cards

LLDP-MED Inventory Management TLV

Used to retrieve hardware characteristics from endpoints, including manufacturer, software version, hardware version, and serial numbers.

11
New cards

Traffic Processing ACL Actions

Actions such as count, drop, redirect (to another port), and mirror that dictate the physical handling of a matched frame.

12
New cards

IGMP Snooping Querier

Manages multicast traffic by sending queries to find group memberships; active receiver entries age out based on these periodic queries.

13
New cards

Non-supplicant Failure Handling

Occurs when a device lacks 802.1X802.1X support; after the Guest authentication delay (default 3030 seconds), the device is placed in the Guest VLAN.

14
New cards

Tail-drop mode

A congestion management behavior where the switch drops all incoming packets once a queue reaches its maximum capacity until space becomes available.

15
New cards

Prelookup ACL Stage

The earliest stage in the switching pipeline where ACLs are processed before any Layer 22 or Layer 33 lookups are performed.

16
New cards

Two-tier Routing Lookup

A mechanism where FortiSwitch first checks the hardware routing table (ASIC) and then falls back to the Forwarding Information Base (FIB) in the kernel.

17
New cards

MCLAG (Multichassis Link Aggregation Group)

Allows two FortiSwitch units to operate as a single logicalAggregation peer, creating a loop-free topology without relying exclusively on STP.

18
New cards

Switch Virtual Interface (SVI)

A virtual interface assigned to a VLAN with an associated IP address that can participate in Layer 33 inter-VLAN dynamic routing.

19
New cards

Broadcast Ethernet Frame

A frame with a destination MAC address set to FF:FF:FF:FF:FF:FFFF:FF:FF:FF:FF:FF, resulting in Layer 22 flooding to all ports in a VLAN domain.

20
New cards

Virtual Domains (VDOMs)

Independent virtual firewalls within a FortiGate used to segment network operations and the multi-tenant administration of managed FortiSwitch devices.

21
New cards

FortiLink over VXLAN

A method used to deploy managed FortiSwitch units at remote sites by tunneling Layer 22 traffic over a Layer 33 WAN underlay.

22
New cards

FortiLink Heartbeat

A continuous keepalive mechanism where a managed FortiSwitch sends Type 55 packets to the FortiGate to verify management tunnel health.

23
New cards

VLAN 4094

The reserved VLAN ID used exclusively for FortiLink management and control-plane traffic between FortiGate and FortiSwitch.

24
New cards

VLAN 4095

The reserved VLAN ID automatically assigned when a physical port is converted into a Routed VLAN Interface (RVI).

25
New cards

802.1X MAC-based Authentication

Authentication mode that treats each MAC address as a distinct session, allowing different access levels for multiple devices on one port.

26
New cards

Loop Guard MAC-Move Detection

An enhancement that monitors for MAC flapping events across ports or VLANs to detect loops beyond the native VLAN.

27
New cards

IGMP Snooping Proxy

A feature that handles IGMP reports locally, only forwarding a join when the first member arrives and a leave when the last member departs a group.

28
New cards

Hardware-based Routing

Routing decisions performed at wire speed directly in the switch ASIC using a hardware-programmed Forwarding Information Base (FIB).

29
New cards

Sniffer Profile

A persistent packet capture method that allows administrators to capture traffic across all switch ports, trunks, and management interfaces simultaneously.

30
New cards

Virtual Port Pool (VPP)

A pool of physical switch ports that can be virtualized and distributed across different VDOMs for multi-tenant isolation.

31
New cards

DAI (Dynamic ARP Inspection)

A Layer 22 security feature that intercepts ARP packets on untrusted ports and validates them against the trusted DHCP snooping database.