| Description | The article describes a known issue that can cause SFP ports 17-24 (1G) to stay down between FortiGate and FortiSwitches or third-party switches. |
| Scope | FortiGate-120G/121G before v7.2.11, v7.4.8, v7.6.3 |
| Solution |
In earlier 120G/121G firmware versions, 'set speed 1000full' for affected ports is incorrectly similar to 'set speed auto'. This is a known issue 1104410 and fixed in v7.2.11, v7.4.8, and v7.6.3 and later.
diagnose hardware deviceinfo nic port21
The FortiSwitch-244E-POE ports 27 and 28 are up.
diagnose switch trunk list
Switch Trunk Information, primary-Channel Trunk Name: _FlInK1_MLAG0_ Active Port Up Time port27 0 days,0 hours,3 mins,24 secs Non-Active Port Status
status: up slave: port27 <-- slave: port28b
In affected firmware versions, if auto-negotiation must be disabled this must be done using a FortiGate internal switch command.
The following command disables auto-negotiate for all SFP ports not just port21. diagnose sys bcm_intf cli 'port ge0-ge3,ge20-ge23 an=0'
If configuring FortiGate for 1000full, an administrator must configure the matching speed setting manually on the neighboring FortiSwitch ports. The same issue can affect FortiGate connections to other switches.
Link down after upgrade to fixed version: If a link was up before the upgrade to a fixed version, the link is down after the upgrade, and the link is configured with 'set speed 1000full', then this may be a pre-existing interface misconfiguration that was hidden by the known issue. In this case, it is recommended to configure 'set speed auto' in case that brings up the link. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.