Hot!I Cannot estabilsh the connection between FortiGate 1000D And FortiGate 3700D

Author
SayedWafi
New Member
  • Total Posts : 5
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/07/22 00:34:11
  • Status: offline
2019/07/22 02:28:17 (permalink)
0

I Cannot estabilsh the connection between FortiGate 1000D And FortiGate 3700D

Greetings All, 
 
we are trying to establish the connection between FrtiGate1000D and FortiGate 3700D through the Fiber Optic.
and we have checked the connectivity plus the SFP but still, the connection not working between them
 
the SFP in both sides is 1G and the port has been enabled in both side as auto.
 
does the lack of license the reason of this issue for the connectivity between the FortiGate.
 
Please find the attached FYR.
 

Attached Image(s)

#1

6 Replies Related Threads

    Dave Hall
    Expert Member
    • Total Posts : 1458
    • Scores: 160
    • Reward points: 0
    • Joined: 2012/05/11 07:55:58
    • Location: Canada
    • Status: offline
    Re: I Cannot estabilsh the connection between FortiGate 1000D And FortiGate 3700D 2019/07/22 06:49:37 (permalink)
    0
    Very doubtful an expired licensing would affected physical connections unless you have firewall policies on the ports with expired UTM policies applied to them.
     
    Are you trying to connect both fgts through a fiber switch or direct-to-direct ports on each fgt?  Have you performed diag hardware device info <nic name> on the CLI to see if there is a duplex/speed or any rx/tx errors (do these error counters grow?)
     

    NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
    #2
    rwpatterson
    Expert Member
    • Total Posts : 8404
    • Scores: 195
    • Reward points: 0
    • Joined: 2006/08/08 10:08:18
    • Location: Long Island, New York, USA
    • Status: offline
    Re: I Cannot estabilsh the connection between FortiGate 1000D And FortiGate 3700D 2019/07/22 07:46:38 (permalink)
    0
    Do you get link lights? Perhaps the fiber needs flipping. (send-send and receive-receive won't work)

    -Bob - self proclaimed posting junkie!
    See my Fortigate related scripts at: http://fortigate.camerabob.com

    -4.3.19-b0694
    FWF60B
    FWF80CM (4)
    FWF81CM (2)
     
    #3
    SayedWafi
    New Member
    • Total Posts : 5
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 00:34:11
    • Status: offline
    Re: I Cannot estabilsh the connection between FortiGate 1000D And FortiGate 3700D 2019/07/22 22:39:37 (permalink)
    0
    Thanks Dave for your reply,
    we are trying to connect both of FortiGate by direct-to-direct ports on each FortiGate
     
    also, FOC as a physical is working correctly 
    about the interface port in both FortiGate is configured as 1G (Auto)
    #4
    SayedWafi
    New Member
    • Total Posts : 5
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 00:34:11
    • Status: offline
    Re: I Cannot estabilsh the connection between FortiGate 1000D And FortiGate 3700D 2019/07/22 22:41:23 (permalink)
    0
    Thanks rwpatterson,
     
    yes, the light between the Fiber is working fine and SFP in the both FortiGate is 1GB
    #5
    SayedWafi
    New Member
    • Total Posts : 5
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/07/22 00:34:11
    • Status: offline
    Re: I Cannot estabilsh the connection between FortiGate 1000D And FortiGate 3700D 2019/07/22 22:44:29 (permalink)
    0
     
    Dave, 
     
    could you see the below link and explain it to me? does it related to the same subject??
     
    https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-hardware-acceleration-52/np6-fgt-1000D.htm?Highlight=FortiGate-1000D
    #6
    Toshi Esumi
    Expert Member
    • Total Posts : 1624
    • Scores: 137
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: I Cannot estabilsh the connection between FortiGate 1000D And FortiGate 3700D 2019/07/23 08:55:35 (permalink)
    0
    NPU architecture for those models wouldn't affect to "make or break" situations. It just doesn't accelerate as it's capable of. If traffic comes in NPU0 port and encrypted for VPN and goes out NPU1 port, the CPU does the work relaying between them instead of the ASIC. 
    I would check the counter increments in "diag hard device nic" then run sniffer on the receiving side if they're actually arriving at the incoming port.
    #7
    Jump to:
    © 2019 APG vNext Commercial Version 5.5