Configuring interfaces

Network configuration

 

 

4Set the MTU size.

Set the maximum packet size in the range of 68 to 1500 bytes. The default MTU size is 1500. Experiment by lowering the MTU to find an MTU size for best network performance.

Configuring port4/ha

You can use port4/ha as a firewall interface or for communication between FortiGate-400 units in an HA group. To configure port4/ha as a firewall interface, you must disable its HA functionality. You can then add the interface to a zone and configure its IP address and netmask. The zone should match the type of network connected to the interface. For example, if you are connecting port4/ha to an internal network, add it to the Internal zone.

Configuring port4/ha for HA mode

To connect two or more FortiGate-400 units in high availability mode, you must set their port4/ha interfaces to HA mode. In HA mode, you cannot connect port4/ha to a network and you cannot add VLAN subinterfaces to it. It can only be connected to the port4/ha of the other FortiGate-400 units in the HA group. The FortiGate-400 units in the HA group use this connection to communicate status and configuration information among the members of the HA group.

To configure port4/ha for HA mode:

1Go to System > Network > Interface.

2For port4/ha, select Modify .

3Select Work as HA to configure the interface for HA operation.

When port4/ha is configured for HA operation, you cannot connect this interface to a network.

4Select OK to save your changes.

Configuring port4/ha as a firewall interface

To configure port4/ha to operate as a firewall interface, disable HA functionality and add port4/ha to a zone:

1Go to System > Network > Interface.

2For port4/ha, select Modify .

3Make sure that Work as HA is not selected.

4Select OK to save your changes.

Configuring the management interface (Transparent mode)

In Transparent mode, you configure the management interface for management access.

1Go to System > Network > Management.

2Change the Management IP and Netmask as required.

This must be a valid address for the network from which you will manage the FortiGate unit.

138

Fortinet Inc.

Page 138
Image 138
Fortinet 400 manual Configuring port4/ha for HA mode, Configuring port4/ha as a firewall interface, 138