Hi all,
i have a Fortigate 200b, firmware 5.2.5
I would like to create an aggregate using 3 Ports, but i want first to clarify some doubts.
1) I want to start using 2 Network Ports, then add a third one later: is this possible?
2) At the moment i have only 1 port available. The second port - port 13 - is bound to a Local-in policy (see attachment).
Question is: how can i deassociate this port from the policy?
Thanks in advance to all
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
1st you have to find everything associated to that port.
( cli )
diag sys checkused system.interface.name port13
( web)
just click on the reference item tabs
Now,
delete and undo all items and then you can build a AE interface with the 2x ports in the Aggregate Ethernet.
PCNSE
NSE
StrongSwan
Hi Emnoc,
thanks for the answer.
I have succesfully created the aggregate with 2 ports (port 13 and port 14).
Now i want to ad port 9 to the aggregate.
When i go into the menu (clicking "edit") i don't have the option to add further ports.
Question: may i add additional ports to the aggregate in a second time?
Thank you
Agianna wrote:I have succesfully created the aggregate with 2 ports (port 13 and port 14).
Now i want to ad port 9 to the aggregate.
Hi,
LACP on a 200B will not be possible with ports 13,14 and 9. This is due to the NP2 chip which drives ports 13-16. You can only add Port 15 and 16 to this aggregate!
Br,
Roman
This is a good new.
Adding Port 9 was just a test to understand if i could add a further port in the future.
So you can confirm that i can add port 15 or 16 to an already exixting aggregate?
Thank you very much for answering
Yes - you should be able to add ports 15 or 16 to that aggregate - if these ports are not configured any other way before adding.
Also be aware that LACP works best, when using 2^n interfaces for an aggregate (meaning 2,4,8,.. ports to the group)
Br,
Roman
Thank you.
I will add port 15, even if it's already configured.
I have first to create a copy of all the policies and settings on the port 15, and iwill bind them to the current aggregate.
Then i delete all is configured on port 15, then i add the port to the aggregate.
Hope it works
Just an advice:
do all what you've posted but do it on a current backup config file. Then restore this config file and after the reboot you'll have everything in place.
In the config file you can search&replace port names easily, IMHO it's much less work this way.
I haven't done it myself but wouldn't "append member <interface-name>" work to add a member to an LACP port so that you don't have to reboot the box.
My comment above was a question. I forgot to type '?' at the end.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.