Hi Myles,Thanks for getting back to me so swiftly.
Hardware switches have much higher port density and forwarding rates than software based switches. The performance of Cisco switches can be easily found in their literature. By the way, a ASR 1000 is a router, not a switch.
As per my standard practice before start configure Fortigate Firewall, i will change the Firewall to Interface mode which physical interfaces of the FortiGate unit are configured and handled individually, with each interface having its own IP address. Reasons for doing this include additional hardware port for routing, or additional ports for difference network.There is a scenario that my customer would like to use some of the ports of the Fortigate Firewall as a switch port with same subnet. To achieve my customer requirement, implementation of Software Switch in Fortigate Firewall can meet my customer requirement.