Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mrandrew
New Contributor II

Fortigate 800C SFP+ Port

Will the FG-TRAN-GC (1000baseTX) SFP work in the SFP+ port of an 800C?  

 

I can do this with Cisco SFP+ ports.  They will take any 1Gig or 10Gig SFP.

 

You may be asking why.  Why use the SFP+ port when you have 4 other SFP 1Gig ports available.  I have 2 Fortigate 800C devices in HA.  One 800C is at the main site and the other is connected at the DR site.  HA runs over a 1Gig dedicated fiber.  The switch at the main site can utilize 10Gig, but the switch at the DR site does not have 10Gig ports.  

 

Thanks

Andrew

Andrew
2 Solutions
mrandrew
New Contributor II

emnoc,

 

Thanks for reply.  I forgot that these FG800Cs shipped with 2 1Gig fiber SFPs.  I placed one into port 24.  I was required to set the port to speed 1000full in order for it to link to the Cisco switch.  The bad thing now is that when I make this change on the port it makes the change on the other Fortigate.  I want one FG800 to run at 10GB and the other at 1GB.  Unless there is a way to manually set each firewall independent of HA, then I'm stuck finding another way or purchasing a 10GB option for the DR site.

 

Thanks again,

 

Andrew

Andrew

View solution in original post

Andrew
ede_pfau
Esteemed Contributor III

I was running into a similar requirement lately. Customer was about to upgrade his 1 Gbps WAN link to 10 Gbps. To keep the configuration identical (that is, the port number before/after) I wanted to use an SFP plug now and an SFP+ plug later in the same 10GE-port. In contrast to the docs which simply state "SFP+ port will accept SFP transceiver as well", the link didn't come up.

 

-> apparently there is no auto-negotiation if you use an SFP transceiver in an SFP+ port. If you pin it down to "1000full" it'll work. [Too late for me.]


Ede

"Kernel panic: Aiee, killing interrupt handler!"

View solution in original post

Ede"Kernel panic: Aiee, killing interrupt handler!"
11 REPLIES 11
mrandrew
New Contributor II

emnoc,

 

Could you please elaborate?  I don't understand what you are saying.  I would assume that there was some reason why Fortinet added (2) 10Gbps ports to the 800C.  I can understand that maybe the processing on the firewall would limit actual throughput a little.  I would think though that for standard layer3, layer4 traffic that I could at least get 10Gbps.  Also keep in mind that the inside LACP is handling all traffic for inside subnets.  These subnets are primarily made up of internal servers and internal workstations (DNS, AD, File, Print, etc).  I would think that I could get at least 10Gbps from a workstations to the AD server.

 

Thanks,

 

Andrew

Andrew

Andrew
ede_pfau
Esteemed Contributor III

The NP4 is capable of 10 Gbps throughput for accelerated traffic (i.e., if all conditions are met). So bundling 2 10 GbE ports is theoretically overprovisioning. But if you want 10 G max througput and link redundancy I don't see any other way to implement it.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors