FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pjang
Staff
Staff
Article Id 344778
Description

This article describes a known issue with the SFP+ interfaces (specifically port9 through port24) on the FortiGate-1000F/1001F model. This issue does not affect the SFP28 interfaces (port25 through port32), nor does it affect the QSFP28 interfaces (port33 and port34).

Scope

FortiGate-1000F/1001F (herein referred to as FortiGate-100xF).

Solution

The issue is triggered when a 1Gbps SFP transceiver is used with the FortiGate-100xF's SFP+ interfaces (specifically port9 through port24). The issue does not occur when using 10Gbps SFP+ transceivers with these same interfaces, and as noted earlier this issue does not affect the other network interfaces on the FortiGate-100xF.

 

When the issue is triggered, the following symptoms can be observed:

  • The interface LEDs on the SFP+ interfaces are not illuminating after connecting the FortiGate to another device.
  • When checking the speed settings of the SFP+ interfaces (get hardware nic <intf_name> | grep -fi speed -A 1), the negotiated Speed and Duplex will show as 10 and Full respectively (i.e. 10Mbps full-duplex) rather than the expected 1000Mbps full-duplex that the link is configured for.

 

Note that even though the interface LEDs are not lit and the interface speed is reported as 10full, network connectivity to the remote device via the SFP link will be working correctly and traffic will be able to flow over the link (i.e. this is a cosmetic issue and not a network-impacting issue).

 

With that being said, the Fortinet development team is working on resolving this issue. The issue is being tracked with Issue ID #1032018, and a solution will be provided in the upcoming FortiOS 7.2.11, 7.4.6, and 7.6.1 releases.

 

Recommendations:

  • As noted above, this is a visual issue and not a network-impacting issue. If 1Gbps SFP links are required from the FortiGate-100xF to another device then continue to implement them as normal, then check network functionality by sending test traffic over the link (i.e. ICMP pings to the remote device via the SFP link).
  • Alternatively, use 10Gbps SFP+ transceivers with the FortiGate-100xF's port9 through port24 interfaces instead, as they do not trigger this issue.