FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kdharan
Staff
Staff
Article Id 419059
Description This article describes an issue where Ultra Low latency (ULL) x5-x8 interfaces connected to 25 gigabyte SFP28 cables connected to Aruba Switch go down after upgrading to FortiOS 7.4.8.
Scope FortiGate (600F and 900G), FortiOS 7.4.8.
Solution
  1. Check the compatible transceiver used for the FortiGate module. See SFP+ Module compatibility.

  2. Perform a loop-back test between X5-X8 ULL ports in the FortiGate and check if the ports are up. Follow the steps below.

Steps:

  1. Plug in the transceiver: Insert the SFP module into the firewall's SFP port.

  2. Make the loop: Connect the single fiber (or loopback device) so it links the SFP's Tx (transmit) port to its Rx (receive) port.

  3. Check the light: If the SFP's LINK/ACT light turns on and stays solid, the hardware is good. If it is off or flickers, there is a problem.

  4. Confirm in FortiGate:

    • CLI: Log in and run the following command:

 

diagnose hardware deviceinfo nic

 

    • GUI: Go to Dashboard -> System Information -> Network and look for the port status.

 

Simple check: If the port shows Up/Link after making the loopback connection, the SFP port is working correctly.

 

  1. Forward error correcting (FEC) is disabled in both the switch and the FortiGate port.


Configuration on the FortiGate interface:

 

config system interface
    edit <ULL port id>
        set forward-error-correction disable
    next
end

Configuration on the Aruba switch interface:

config
interface <Port>
error-control none
exit
write memory

Related articles: 
Technical Tip: How to check the list of certified transceivers supported by the FortiGate
Technical Tip: How to do a loopback test for SFP ports