FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ap
Staff
Staff
Article Id 366807
Description This article describes migrating an existing physical interface into a newly created aggregate interface and how to resolve the errors that can arise.
Scope FortiGate.
Solution

Note: The 'Integrate Interface' option for interface migration is available from FortiOS v7.0.0 onwards.

 

  1. In this article, physical interface port2 (with Alias LAN) will be moved to an aggregate interface 'LAN-Aggregate'. 'Right-click' interface port2 and select the 'Integrate Interface' option from the drop-down menu OR after selecting port2, select the 'Integrate Interface' option available on top beside the delete button.
                                                                                              
    pic1.png

     

  2. In the next window, select the 'Migrate to Interface' option and select Next:
                                                      
    pic2.png                                                                      
  3. Select 'Create a new interface', enable Port Configuration (Enabling this will port over the configuration of port2 to the target interface. Note that the existing configuration for the target interface will be overwritten.), and give the name of the newly created aggregate interface and select Next.
                                                                    
    pic4.png                                                                                  
  4. A new window will open which shows all the instances that will get replaced. Select 'Create' after reviewing all the information in this window:
                                                                   
    pic6.png                                                                   
  5. A new window will open which will ask for confirmation. Select 'OK' after reviewing all the changes:
                                                                      
    pic7.png                                     
  6. Sometimes, the error 'Failed to save changes' will be thrown in the next step, or the migration will complete successfully as shown in step 7. Check step 8 for possible reasons for the error and how to resolve it:
                                                                      
    pic8.png                                                          
  7. If the migration is completed successfully, the following window will be shown with the status 'Updated Entry'. Select 'Close' to complete migration:
                                                                             
    pic17.png

     

  8. If the aforementioned error is received, the below configuration issues can be responsible:
  • Interface Port2 can be part of monitored interfaces under HA configuration. Remove Port2 from the monitored interfaces.

    config system ha
        set group-id 100
        set group-name "HA"
        set hbdev "port2"  <------Check this if anything is in there.

  • Port2 addressing mode is set to DHCP. Switching to manual mode will make it possible to add the interface.

Note: This configuration can be overlooked, as even though the 'Reference' section of the interface shows '0' reference, it can still be referenced in these places under HA configuration and 'source IP'. Pay close attention to these configurations. 

 

  • Port2 interface IP could have been used as source IP under other configurations as shown in the below image. Remove all the references where the Port2 interface IP is configured as source IP. There is no need to remove the Port2 interface IP. Only remove where it is used as source-ip:

 

pic14.png

 

Related article:

Technical Tip: How to migrate a referenced interface