Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Agianna
New Contributor

Creating 802.3 aggregate

Hi all,

 

i have a Fortigate 200b, firmware 5.2.5

I would like to create an aggregate using 3 Ports, but i want first to clarify some doubts.

 

1) I want to start using 2 Network Ports, then add a third one later: is this possible?

 

2) At the moment i have only 1 port available. The second port - port 13 -  is bound to a Local-in policy (see attachment).

Question is: how can i deassociate this port from the policy?

 

Thanks in advance to all

9 REPLIES 9
emnoc
Esteemed Contributor III

1st you have to find everything associated to that port.

 

( cli )

 

 diag sys checkused system.interface.name port13

 

( web)

 

just click on the reference item tabs

 

Now,

delete and undo all items and then you can build a AE interface  with the 2x ports in the Aggregate Ethernet.

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Agianna
New Contributor

Hi Emnoc,

 

thanks for the answer.

I have succesfully created the aggregate with 2 ports (port 13 and port 14).

 

Now  i want to ad port 9 to the aggregate.

When i go into the menu (clicking "edit") i don't have the option to add further ports.

Question: may i add additional ports to the aggregate in a second time?

 

Thank you

romanr
Valued Contributor

Agianna wrote:

I have succesfully created the aggregate with 2 ports (port 13 and port 14).

 Now  i want to ad port 9 to the aggregate.

Hi,

 

LACP on a 200B will not be possible with ports 13,14 and 9. This is due to the NP2 chip which drives ports 13-16. You can only add Port 15 and 16 to this aggregate!

 

Br,

Roman

Agianna
New Contributor

This is a good new.

Adding Port 9 was just a test to understand if i could add a further port in the future.

 

So you can confirm that i can add port 15 or 16 to an already exixting aggregate?

 

Thank you very much for answering

romanr
Valued Contributor

Yes - you should be able to add ports 15 or 16 to that aggregate - if these ports are not configured any other way before adding.

 

Also be aware that LACP works best, when using 2^n interfaces for an aggregate (meaning 2,4,8,.. ports to the group)

 

Br,

Roman

Agianna
New Contributor

Thank you.

 

I will add port 15, even if it's already configured.

I have first to create a copy of all the policies and settings on the port 15, and iwill bind them to the current aggregate.

Then i delete all is configured on port 15, then i add the port to the aggregate.

 

Hope it works

 

 

ede_pfau

Just an advice:

do all what you've posted but do it on a current backup config file. Then restore this config file and after the reboot you'll have everything in place.

In the config file you can search&replace port names easily, IMHO it's much less work this way.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Toshi_Esumi

I haven't done it myself but wouldn't "append member <interface-name>" work to add a member to an LACP port so that you don't have to reboot the box.

Toshi_Esumi

My comment above was a question. I forgot to type '?' at the end.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors