Skip to main content
simonorch
Explorer
September 21, 2015
Question

Link Aggregation does not work with 10Gbps interfaces on certain models?

  • September 21, 2015
  • 10 replies
  • 17537 views

I was informed today that certain models do not support link aggregation of their 10Gbps interfaces, specifically the 900D and 1000D, or perhaps it's better to say that it doesn't work.

 

Is this true?

If so, are there other models that don't support this, like the 600D?

    10 replies

    emnoc
    New Member
    September 21, 2015

    I haven't  heard that, but you only have 2x 10gige ports. Unless they are on some limit fabric maybe this a limitation in the hardware.

     

    A SSE from FTNT could better answer any limitation within the  2port ( 10gige )  FGT models.

    simonorch
    simonorchAuthor
    Explorer
    September 21, 2015

    I actually heard this from a FTNT SE but can't seem to find anything on it in any documentation, so wanted to throw this one out their for further comment. As i understood it it's a hardware limitation?

     

    It doesn't seem to be a problem on the 800C and 1000C and we have a good few customers link aggregating their 10gig interfaces on those models.

    emnoc
    New Member
    September 21, 2015

    Could be,  but we have Link Aggregation on 2x10GIGE interfaces on the 1500D. I believe this chassis is built on the same base hardware of that of a  900/1000D but just with more 10gige ports ;)

     

    Did you SE say what fortiOS version where effected? and if any CSB was drafted?

     

    Ken

    simonorch
    simonorchAuthor
    Explorer
    September 21, 2015

    As i understand it, the 1200D and 1500D  are OK and that this is not firmware related but hardware. 

     

    If there is a limitation, then fair enough, but it needs to be communicated effectively in the documentation.

     

    That's pretty much all i've heard.

    ede_pfau
    SuperUser
    SuperUser
    September 21, 2015

    This is a hardware limitation, independent of the FortiOS version.

    This affects the FG-900D and the 1000D - with 2 NP6 and no ISF.

     

    These models simply do not have an Internal Switch Fabric (ISF) connecting the NP6s. One NP6 can support up to 4 10G ports but on the affected models, one NP6 is wired to one 10G and several 1G ports. So you cannot combine 10G ports.

     

    IMHO this is one of the rare hardware limitations which should be known to Fortinet partners beforehand. My local SE has stressed this point in our last meeting without being questioned so he did what he could do.

     

    (edit: affected models)

    simonorch
    simonorchAuthor
    Explorer
    September 22, 2015

    Nicely buried in the hardware acceleration for FortiOS 5.2 documentation i found this..

     

    The increase in offloading capacity offered by LAGs and multiple NP6s is supported by the integrated switch fabric (ISF) that allows multiple NP6 processors to share session information. Most FortiGate units with multiple NP6 processors also have an ISF. However, the FortiGate-1000D does not have an ISF. On this model and others that have more than one NP6 and no ISF, if you attempt to add interfaces connected to different NP6 processors to a LAG the system displays an error message.

     

    emnoc
    New Member
    September 22, 2015

    Interesting notes but I'm not surprised. This is why POCs are crucial and you need to test what your  needs are now and any possible needs in the future. I'm so glad we went with  1500D.

    Ken

    simonorch
    simonorchAuthor
    Explorer
    September 23, 2015

    A follow up on this, i've found out that the 600D is not affected as it only has the one NP6

     

    There's also a useful Fortinet blog post about the NP6 platform architecture 

     

    https://blog.fortinet.com/post/optimizing-your-network-design-with-the-np6-platform

     

     

    dressel
    New Member
    September 23, 2015

    That's right regarding the 900D.

    The two 10G ports are located on different NPs and there is no internal switch fabric.

     

    I've received this information from a Fortinet SE at a partner meeting in Frankfurt, Germany.

    dwear
    New Member
    November 14, 2017

    In case anyone stumbles across this as I did, here is a link that shows the architecture of the NP6 on the 1000D. The links on the right show other models. 

     

    http://help.fortinet.com/...n-52/np6-fgt-1000D.htm

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!