Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SayedWafi
New Contributor

I Cannot estabilsh the connection between FortiGate 1000D And FortiGate 3700D

Greetings All, 

 

we are trying to establish the connection between FrtiGate1000D and FortiGate 3700D through the Fiber Optic.

and we have checked the connectivity plus the SFP but still, the connection not working between them

 

the SFP in both sides is 1G and the port has been enabled in both side as auto.

 

does the lack of license the reason of this issue for the connectivity between the FortiGate.

 

Please find the attached FYR.

 

6 REPLIES 6
Dave_Hall
Honored Contributor

Very doubtful an expired licensing would affected physical connections unless you have firewall policies on the ports with expired UTM policies applied to them.

 

Are you trying to connect both fgts through a fiber switch or direct-to-direct ports on each fgt?  Have you performed diag hardware device info <nic name> on the CLI to see if there is a duplex/speed or any rx/tx errors (do these error counters grow?)

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
rwpatterson
Valued Contributor III

Do you get link lights? Perhaps the fiber needs flipping. (send-send and receive-receive won't work)

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
SayedWafi

Thanks rwpatterson,

 

yes, the light between the Fiber is working fine and SFP in the both FortiGate is 1GB

SayedWafi

Thanks Dave for your reply,

we are trying to connect both of FortiGate by direct-to-direct ports on each FortiGate

 

also, FOC as a physical is working correctly 

about the interface port in both FortiGate is configured as 1G (Auto)

SayedWafi

 

Dave, 

 

could you see the below link and explain it to me? does it related to the same subject??

 

https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-hardware-acceleration-52/np6-fgt-100...

Toshi_Esumi

NPU architecture for those models wouldn't affect to "make or break" situations. It just doesn't accelerate as it's capable of. If traffic comes in NPU0 port and encrypted for VPN and goes out NPU1 port, the CPU does the work relaying between them instead of the ASIC. 

I would check the counter increments in "diag hard device nic" then run sniffer on the receiving side if they're actually arriving at the incoming port.

Labels
Top Kudoed Authors