FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nsubramanian
Staff
Staff
Article Id 197502

Description

 

This article describes the feature when Small Form-Factor pluggable (SFP) transceivers are installed on the FortiGate, issues may be encountered with establishing a valid physical link.

Symptoms include associated ports being shown with the link down (red arrow icon) on the GUI and link lights on the FortiGate device for the associated ports not indicating a link.

In this case, it is worthwhile to verify the FortiGate configuration for the associated port.

Scope

 

All FortiGate models have SFP Modules.

Solution

 

This command is only available on certain of the FortiGate D-series models, such as the FortiGate 100D, 240D, 1500D, 3700D, 3810D, and 3815D.  The device must also be running FortiOS 5.4.x.

 

To verify if FortiGate unit interfaces are supporting transceiver or not, run the below command and press enter to see the list of interfaces :

 

get sys interface transceiver
Interface port15 - Transceiver is not detected.
Interface port16 - Transceiver is not detected.
Interface port17 - Transceiver is not detected.
Interface port18 - Transceiver is not detected.

 

As per the output, the transceiver can be plugged on interface between port15 - port18.


The command to use is 'get system interface transceiver' to retrieve information for all interfaces that support SFP transceiver or 'get system interface transceiver <interface>' for a single interface.


The sample result is as below:

 

get sys interface transceiver

Interface port1: SFP or QSFP transceiver is not detected.

Interface port2: SFP or QSFP transceiver is not detected.

Interface port3: SFP or QSFP transceiver is not detected.
Interface port4: SFP or QSFP transceiver is not detected.
Interface port5: SFP or QSFP transceiver is not detected.
Interface port6: SFP or QSFP transceiver is not detected.
Interface port7: SFP or QSFP transceiver is not detected.
Interface port8: SFP or QSFP transceiver is not detected.
Interface port9: SFP/SFP+
  Vendor Name: Axcen Photonics
  Part No.   : AXXE-5886-05B1
  Serial No. : AX14170008967
Interface port10: SFP or QSFP transceiver is not detected.
Interface port11: SFP/SFP+
  Vendor Name: FIBERXON INC.
  Part No.   : FTM-8012C-SL
  Serial No. : A8660061719307
Interface port12: SFP or QSFP transceiver is not detected.
Interface port13: SFP or QSFP transceiver is not detected.
Interface port14: SFP or QSFP transceiver is not detected.
Interface port15: SFP or QSFP transceiver is not detected.
Interface port16: SFP or QSFP transceiver is not detected.
Interface port17: SFP or QSFP transceiver is not detected.
Interface port18: SFP or QSFP transceiver is not detected.
Interface port19: SFP or QSFP transceiver is not detected.
Interface port20: SFP or QSFP transceiver is not detected.
Interface port21: SFP or QSFP transceiver is not detected.
Interface port22: SFP or QSFP transceiver is not detected.
Interface port23: SFP or QSFP transceiver is not detected.
Interface port24: SFP or QSFP transceiver is not detected.
Interface port25: SFP or QSFP transceiver is not detected.
Interface port26: SFP or QSFP transceiver is not detected.
Interface port27: SFP or QSFP transceiver is not detected.
Interface port28: SFP or QSFP transceiver is not detected.
Interface port29: SFP or QSFP transceiver is not detected.
Interface port30: SFP or QSFP transceiver is not detected.
Interface port31: SFP or QSFP transceiver is not detected.
Interface port32: SFP or QSFP transceiver is not detected.
Interface port33: SFP or QSFP transceiver is not detected.
Interface port34: SFP or QSFP transceiver is not detected.
Interface port35: SFP or QSFP transceiver is not detected.
Interface port36: SFP or QSFP transceiver is not detected.
Interface port37: SFP or QSFP transceiver is not detected.
Interface port38: SFP or QSFP transceiver is not detected.
Interface port39: SFP or QSFP transceiver is not detected.
Interface port40: SFP or QSFP transceiver is not detected.
Interface port41: SFP or QSFP transceiver is not detected.
Interface port42: SFP or QSFP transceiver is not detected.
Interface port43: SFP or QSFP transceiver is not detected.
Interface port44: SFP or QSFP transceiver is not detected.
Interface port45: SFP or QSFP transceiver is not detected.
Interface port46: SFP or QSFP transceiver is not detected.
Interface port47: SFP or QSFP transceiver is not detected.
Interface port48: SFP or QSFP transceiver is not detected.

                                      Optical    Optical    Optical
SFP/SFP+      Temperature  Voltage    Tx Bias    Tx Power   Rx Power
Interface     (Celsius)    (Volts)    (mA)       (dBm)      (dBm)
------------  -----------  ---------  ---------  ---------  --------
       port9   34.1         3.31       6.35       -1.9      -40.0 --
      port11   N/A          N/A        N/A        N/A        N/A
  ++ : high alarm, + : high warning, - : low warning, -- : low alarm, ? : suspect

 

get sys interface transceiver port39  <-- Output for a single interface.

 

Interface port39 - QSFP+/QSFP28 (4 x 25.8G)
Diagnostics : Rx Avg Power Tx Power
Vendor Name : FINISAR CORP <<<<< Vendor name
Part No. : FTLC9551REPM <<<<<< Part number
Serial No. : X2KA3VZ
Measurement Unit Value High Alarm High Warning Low Warning Low Alarm
------------ ------------ ------------ ------------ ------------ ------------ ------------


Full output in the below screenshot:

 

SFP.PNG

 

Additionally, run the below command for further information about the affected interface status and counters, i.e. possible drops or errors

 

diagnose hardware deviceinfo nic <affected_port>

show system interface <affected_port>

 

Note:

During the troubleshooting process, it is good practice to make sure the transceivers and the fiber cables are matching in single mode or multimode. It is a single-mode transceiver the fiber cable has to be single-mode, if the transceiver is in a multimode the fiber cable has to be in a multimode.