FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nalexiou
Staff
Staff
Article Id 333005
Description This article describes an issue users face with missing speed options on 10xF models after upgrading to FortiOS v7.2.8 or v7.4.2 and later.
Scope FortiGate-100F/101F. v7.2.8 or v7.4.2
Solution

FortiGate-100F/101F has 28 total ports. See the data sheet for more information.

 

In FortiOS v7.2.7 or before, the following speed options are available for WAN1, Port15, Port17 (Shared SFP), Port19 (Shared RJ45) and X1 (SFP+):  

 

conf sys interface  

edit wan1 <- RJ45 ethernet connection.

set speed 

auto        Automatically adjust speed. 

10full      10M full-duplex. 

10half      10M half-duplex. 

100full     100M full-duplex. 

100half     100M half-duplex. 

1000full    1000M full-duplex. 

next 

edit port15 <- SFP Fiber connection.

set speed 

auto        Automatically adjust speed. 

1000full    1000M full-duplex. 

next 

edit port17 <- Shared port using SFP fiber connection.

set speed  

auto        Automatically adjust speed.  

10full      10M full-duplex.  

10half      10M half-duplex.  

100full     100M full-duplex.  

100half     100M half-duplex.  

1000full    1000M full-duplex.  

next 

edit port19 <- Shared port using RJ45 ethernet connection.

set speed 

auto        Automatically adjust speed. 

10full      10M full-duplex. 

10half      10M half-duplex. 

100full     100M full-duplex. 

100half     100M half-duplex. 

1000full    1000M full-duplex. 

next 

edit x1 <----- SFP+ Fiber connection

set speed 

auto         Automatically adjust speed. 

1000full     1000M full-duplex. 

10000full    10G full-duplex. 

10000auto    10G auto. 

 

After the upgrade to v7.2.8 or v7.4.2, some speed options on these ports are missing, regardless of port media type (RJ45 or SFP or SFP+). 

In FortiOS v7.2.8 or v7.4.2, the following speed options are available for those same ports: 

  

conf sys interface 

edit  wan1 <- RJ45 ethernet connection.

set speed 

auto    Automatically adjust speed. 

next 

edit port15 <- SFP Fiber connection.

set speed 

1000full    1000M full-duplex. 

1000auto    1000M auto-negotiation. 

next 

edit port17 <- Shared port using SFP fiber connection.

set speed 

1000full    1000M full-duplex. 

1000auto    1000M auto-negotiation. 

next 

edit  port19 <- Shared port using RJ45 ethernet connection.

set speed 

1000full    1000M full-duplex. 

1000auto    1000M auto-negotiation. 

next 

edit  x1 <- SFP+ Fiber connection.

set speed 

1000full     1000M full-duplex. 

10000full    10G full-duplex. 

  

 This is a known issue (tracked under bug ID 989629) which is resolved in later FortiOS versions.

As of FortiOS v7.2.9, v7.4.5 and v7.6.0, the FortiGate-100F/101F will support the following speed settings for ports under config system interface: 

  • Copper/RJ45 (DMZ, MGMT, HA1, HA2, WAN1, WAN2, Port1-Port12 and Port17 to Port20) - 10full, 10half, 100full, 100half, 1000full and auto 
  • Fiber SFP (Port13-Port16 and Port17 to Port20) - 1000full and auto 
  • Fiber SFP+ (X1 and X2) - 1000full and 10000full 

 

For example: in FortiOS v7.6.0, the ports will show the following speed options, as shown below: 

 

conf sys interface 

edit wan1 

set speed 

auto        Automatically adjust speed. 

10full      10M full-duplex. 

10half      10M half-duplex. 

100full     100M full-duplex. 

100half     100M half-duplex. 

1000full    1000M full-duplex. 

next 

edit port15 

set speed 

auto        Automatically adjust speed. 

1000full    1000M full-duplex. 

next 

edit port17 

set speed 

auto        Automatically adjust speed. 

1000full    1000M full-duplex. 

next 

edit port19 

set speed 

auto        Automatically adjust speed. 

10full      10M full-duplex. 

10half      10M half-duplex. 

100full     100M full-duplex. 

100half     100M half-duplex. 

1000full    1000M full-duplex. 

next 

edit x1 

set speed 

1000full     1000M full-duplex. 

10000full    10G full-duplex. 

  

The shared ports Port17 and Port19 have SFP and RJ45 connections, respectively. This is recognized by FortiGate and reflected in the available speed options.

Upgrade Note:
When upgrading FortiGate 100F/101F from a previous firmware version to any firmware version v7.2.8, v7.4.2 or later, the configured speed of the shared RJ45/SFP ports 17 to 20 will be 'set speed 1000full'. If a different speed setting is required, an administrator must change this manually after upgrade.
For example, upgrading from v7.2.7 to v7.2.9 will set the speed of the affected ports to 1000full. The full behavior is described in the article 'FortiGate-100F/101F has different speed setting for shared RJ45/SFP ports after upgrade to v7.2.8 or...'.

 

Related documents: