Created on
08-08-2022
12:29 AM
Edited on
07-02-2025
07:58 AM
By
Jean-Philippe_P
Description | This article describes the functions of port groups in high-end platforms. |
Scope | FortiGate v6.4, v7.0, and v7.2 GA releases. |
Solution |
In top-end FortiGates, for example, 1800F, 1801F, 2600F, 3400E, 3600E, 4200F, and 4201F, the majority of the physical interfaces are participating in port groups.
Port group can be easily noticed, over the physical interface itself, under the GUI's Network -> Interfaces section:
The above example is from a FortiGate-3600E, and it is easily possible to observe that port3 up to port6 belong to the same group.
A group consists of 4 ports, and the settings like interface speed, media type, and Forward Error Correction [FEC] are the same for all group interface members by default.
When the user changes one of the speed settings, FortiOS generates a warning message and changes the setting to be identical in the other 3 port group members as well.
For example, speed settings were changed only in port33:
config system interface edit port33
Then, all the other three ports in the same group were automatically configured with the same setting:
show system interface edit "port34"
It will not be possible to remove or split the ports separately from the port group members, as it comes by design.
Note: A port group will have the same speed across all its interfaces, due to hardware limitations.
If one interface is not part of an aggregate, it is allowed to change its speed, as long as it is possible to change the speed of all other interfaces of the port group.
As explained, FortiOS does not allow changes in the speed of an interface that is a member of an aggregate, so if other ports of the same port group are members of an aggregate, it will not be possible to change the speed of a physical interface that is not part of an aggregate.
Changing the 'mediatype' option will not be forced on the rest of the group members.
Behavior change from v7.0.2 onwards: As of v7.0.2, and device allows a 1G/10G speed option mixed for ports in the same port group.
Test results from 2601F running v7.2.10:
2601F # show system interface port29
2601F # show system interface port30
2601F # show system interface port31
2601F # show system interface port32 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.