FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ysatake
Staff
Staff
Article Id 384156
Description This article describes how to check the packet counter on the ISF (Integrated Switch Fabric) in the Broadcom chip in FortiGate.
Scope FortiGate-180xF, 260xF, 350xF, 420xF, 440xF, v7.0.x, v7.2.x, v7.4.x, v7.6.x.
Solution

The packet counter of the ISF (Integrated Switch Fabric), which refers to the Broadcom chip, can be checked using the following method.

 

diagnose sys bcm cli "show c"

 

This command displays differential counters. It shows the difference between the previous output and the current output.
To check whether any packet drops are occurring in the ISF, use the following command.

 

diagnose sys bcm cli "show c" | grep DROP

 

The mapping between ISF ports (Broadcom chip ports) and Front Panel ports can be verified using the following command.
In the example below, port1 is mapped to xe25 on the ISF.

 

diagnose npu np7 port-list


image.png

 

Related documents:

FortiGate 1800F and 1801F fast path architecture | FortiGate / FortiOS 7.6.2 | Fortinet Document Lib...

FortiGate 2600F and 2601F fast path architecture | FortiGate / FortiOS 7.6.2 | Fortinet Document Lib...

FortiGate 3500F and 3501F fast path architecture | FortiGate / FortiOS 7.6.2 | Fortinet Document Lib...

FortiGate 4200F and 4201F fast path architecture | FortiGate / FortiOS 7.6.2 | Fortinet Document Lib...

FortiGate 4400F and 4401F fast path architecture | FortiGate / FortiOS 7.6.2 | Fortinet Document Lib...