Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
angrygreenfrogs
New Contributor

60C Link Aggregation

Hi guys, I' ve been googling and searching here, but haven' t found an answer. Does the 60C support link aggregation? The data sheet here: http://www.fortinet.com/sites/default/files/productdatasheets/FortiGate-60C.pdf Says " Multi-Link Aggregation (802.3ad)" However, I' ve seen some internet search mentions of the 60C not supporting link aggregation. Anyone know the truth?
29 REPLIES 29
Carl_Wallmark
Valued Contributor

Then you can use two FG 60C, connect them to two switches and enable spanning tree, i have this setup working with two 110C and two HP Procurve 2910 switches.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Austin_M
New Contributor II

Find out whether 60C supports redundant interfaces or not . If it does then you can combine two interfaces into one for each zone and then have a full mesh setup.
Carl_Wallmark
Valued Contributor

Find out whether 60C supports redundant interfaces or not . If it does then you can combine two interfaces into one for each zone and then have a full mesh setup.
It does not, the 200B is the first model, read my post above.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
angrygreenfrogs
New Contributor

Selective, Austin.M -- thanks guys -- we' ve just received our pair of 60Cs. So I' m digging around into that right now. I' ll post my results to help with others in the future.
emnoc
Esteemed Contributor III

Link aggregation and redundant interfaces are 2 unique features or issues. Also I recall link aggregation ( 802.3ad ) being support in models as early as the 100A and even 800A back in the day, so I' m not sure of what you meant by; The 200B is the first model to support Link Aggregation. 100D does not.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Carl_Wallmark
Valued Contributor

emnoc: i mean, the 110C, 100D, 100A, 80C, 60C, 50B, 40C and 20C does not support these features, and i know in much older firmwares they could have been supported but not in newer firmwares.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
ede_pfau
SuperUser
SuperUser

The reason for this is that in v4.00 LACP is handled by the NP. Smaller FGTs do not have NPs. It might be that in v3.00 LACP was done by the CPU but that would cost a lot of power for GbE interfaces and so was abandoned.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
angrygreenfrogs
New Contributor

Hi guys, Well we got our 60Cs in and I' ve been experimenting with the possible configurations here. I can say these things for a fact, the 60c definitely does not support link aggregation and also does not support interface redundancy. Selective, I think the solution that leaves for me is doing like you' ve suggested and using 2 switch ports.. did you do that by configuring creating a new interface of type " software switch" ?
angrygreenfrogs
New Contributor

Yep, one alternative seems to be to use a software switch, which is available in the 60C. You can create a software switch from " Network" ->" Interface" ->" Create New Interface" , then: Type: Software Switch And select the interface ports desired (e.g. I used internal1 and internal2). I first set my " Switch Mode" into " Interface Mode" to let me have access to internal1-5 and created a LAN switch. You can set a single IP address for the switch, e.g. 192.168.0.5 I ran some tests by running 2 network cables, one from internal1, and another from internal2 out to a switch with a test PC. I setup a constant ping from that test PC back to the 60C 192.168.0.5 address, and then tried unplugging internal1 and then internal2. I found that generally this did work and access to the device would recover.. but it would noticeably take a few seconds (e.g. 5-10) for ping to resume after switching the cables. I assume this is just due to normal switching. So this seems to work, but it' s definitely not as good as a real redundant or aggregate interface. Please let me know if anyone has any knowledge of if using a software switch like this could cause any issues?
Carl_Wallmark
Valued Contributor

My setup was a little different, as i do not want to do software switch, beacuse it will run on the CPU. My setup: 2 FortiGate 110C 2 Procurve switches 2810 from each fortigate (the switch interface), connect two cables, one to each switch. configure spanning-tree on the switches (i went with rapid spanning tree) Then cross-connect the two switches with each other.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors