Skip to main content
nsantin
New Member
July 16, 2012
Question

iSCSI Traffic on Internat Switch

  • July 16, 2012
  • 7 replies
  • 6719 views
Has anyone run iSCSI traffic over the Internal switch on a FGT60-C? Im looking to connect an iSCSI server into the internal switch on a FGT cluster which also two VM servers connected to it. The VM Servers will access the iSCSI box. Anyone see any issues with this?

    7 replies

    Jan_Scholten
    New Member
    July 17, 2012
    No experiences, but i doubt, that the fortigate will inspect iSCSI Traffic, so no security won. Additionally the 60C may not be fast enough to handle loads of (iSCSI ) Traffic. I would not try that.
    RichardH
    New Member
    July 17, 2012
    I agree wtih Jan, not a good idea at all. The spec on the 60C is 1Gbps (firewall throughput), you wont hit it.
    romanr
    New Member
    July 17, 2012
    As long as you only use the switch I dont see any problems... I am not sure if the switch of the FGT-60C will be capable of handling jumbo frames, but I think you won' t really need them in this scenario! br, Roman
    emnoc
    New Member
    July 18, 2012
    Sounds like you should buy a core switch or 2 if I had to guess. Place the iSCSI traffic locally to the VMServers. Their' s no valid reason to run that traffic thru a firewall from what I can see in your diagram.
    nsantin
    nsantinAuthor
    New Member
    July 20, 2012
    The reason im thinking of doing this is to avoid installing more NICs into the servers. currently both servers have 2 nics, which connect to each of my FGT60-C' s " internal ports - switch mode" directly in an A/A cluster. I circumvent any physical switches to reduce potential failure points. we are looking at implementing an iSCSI solution but to get proper redundancy I' ll need 2 more nics on each machine, then 2 more L3 switches (or VLAN my existing cisco switches) if I cant use the FGTs as the switches.
    emnoc
    New Member
    July 20, 2012
    You don' t use more nic you use 802.1q trunking on your core switch. i.e vlan 100 = main-lan vlan 200 = iSCSI then you place the servers in vlan 100 along with the fortigate then you place the servers that needs iSCSI into vlan 200 and NOT the fortigate. Now iSCSI goes to all servers that need it and you don' t worry about any limitations on the FGT 60C ports. And this would also ensure that your iSCSI traffic doesn' t exhaust your 1gig thru-put or 380K sessions limits.
    Yngve0
    New Member
    August 1, 2012
    I have a similar issue; I want to define the two 1Gig-ports on a FG80C as software switch to connect a server and a iSCSI device. Would that work or must I go the hard way and set up an dedicated iSCSI-switch? Y