Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
1. Why someone needs to dedicate a port for sole purpose of management while we could do the same through any other network port or through USB or serial interfaces? 2. Can those ports handle regular network traffic? 3. If the answer to the previous question is " YES" then what make those ports different from other " regular" network ports on the same unit (except word " management" in their name)?1: for out of band management. Ideal when you have a OOB network or some other path. The route table sites as a OOB route-table also 2: not it' s defined for management of the device. Some have dual-management ports. 3: it' s management port.
PCNSE
NSE
StrongSwan
VinAndr originally asked the following questions. I provide the following answers which I think are more accurate and up-to-date. Some of this post is redundant, but it also corrects misinformation about MGMT ports as they apply to Fortinet.
1. Why someone needs to dedicate a port for sole purpose of management while we could do the same through any other network port or through USB or serial interfaces?
Answer 1: As previously stated numerous times in this thread the MGMT ports provide out-of-band management of the unit in question. This is important to organizations that have OOBM infrastructure. The management port can be configured in a number of ways. In more recent FortiOS you have the option to have management ports dedicated to management functions.
config system interface edit mgmt set dedicate-to management next end
When a port is configured as a dedicated management interface its IP/Subnet will not be advertised or participate in routing. It's simply an access port. There are other ways to accomplish this however. For example you can configure VDOM's where the root VDOM is the Management VDOM and traffic is on another VDOM. This provides a lot of flexibility. We could ramble on here for some time so I'll move on.
2. Can those ports handle regular network traffic?
Answer 2: Yes, almost any port on a Fortinet appliance can be tasked to perform any role. The name of the port is just that, a name. However not all ports on Fortinet products are equal (see 3).
3. If the answer to the previous question is " YES" then what make those ports different from other " regular" network ports on the same unit (except word " management" in their name)?
Answer 3: Some ports on FortiGates for are ASIC accelerated and other are not. You will need to check your datasheet to determine which ports are FortiASIC accelerated if any. Most FortiGates usually have at least 2 ASIC accelerated ports. In all cases a port labeled MGMT and HA will NOT be accelerated. This does not mean that you cannot use it as a standard port. It will work just fine, just don't expect too much of it in terms of UTM capability. It will have no problems performing straight up IPSEC, Firewall and light UTM functions. I hope this helps clear the waters.
1. Why someone needs to dedicate a port for sole purpose of management while we could do the same through any other network port or through USB or serial interfaces? 2. Can those ports handle regular network traffic? 3. If the answer to the previous question is " YES" then what make those ports different from other " regular" network ports on the same unit (except word " management" in their name)?1: for out of band management. Ideal when you have a OOB network or some other path. The route table sites as a OOB route-table also 2: not it' s defined for management of the device. Some have dual-management ports. 3: it' s management port.
PCNSE
NSE
StrongSwan
config system interface edit mgmt set dedicate-to management next enddo not process regular traffic. The same interface not dedicated to management may do this. NP Acceleration, as far as documentation shows, likely not, but you may want to double check it for your device: http://docs.fortinet.com/uploaded/files/1607/fortigate-hardware-accel-50.pdf
OK, more specific: dedicated mgmt ports in terms of: config system interface edit mgmt set dedicate-to management next end do not process regular traffic. The same interface not dedicated to management may do this.Perfect! Your answer " glues" everything together. Thank you very much, netmin!
6 x GE RJ45 ports (including 4 x FortiASIC-accelerated ports, 2 x management ports), 4 x GE SFP slots, 120GB onboard storage
PCNSE
NSE
StrongSwan
I would be very very careful trying to use dedicate ports for user traffic and expecting acceleration. You should confirm that, due to the ASIC might not be bound to a " MGMT" interface.I now know (both from netmin' s post as well I checked the doc he was referring to) that management ports are not accelerated. ...and that' s fine - sometimes you need few extra physical ports for low-volume users' and management unrelated traffic. 4 RJ45 ports for a powerful firewall to connect to networks around - is a shame. BTW, neither of SFP ports on both FG-300D and FG-500D are accelerated as well.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.