Fabric channel layer-2 link aggregation

FortiGate-5050 fabric backplane communication

Fabric channel layer-2 link aggregation

FortiSwitch-5003A boards support 802.3ad static mode layer-2 link aggregation and 802.1q VLANs for the fabric channels. You can use these features to configure link aggregation to distribute traffic to multiple FortiGate-5001A or 5005FA2 boards. Link aggregation configurations also support IPv6 traffic and traffic with jumbo frames up to 16 kbytes.

You can use link aggregation to increase the bandwidth capacity of a FortiGate-5000 configuration by distributing network traffic among multiple FortiGate-5001A or 5005FA2 boards. Adding a new FortiGate-5000 board to a trunk results in an almost linear increase in performance. Link aggregation is configured and functions the same way for 1-gigabit and 10-gigabit fabric backplane networks. You can configure 1-gigabit configurations with FortiGate- 5001A or 5005FA2 boards. You can configure 10-gigabit configurations with FortiGate-5001A boards combined with FortiGate-RTM-XB2 modules. FortiGate- RTM-XB2 modules also increase performance by added NP2 acceleration to the configuration.

You configure link aggregation by adding FortiSwitch-5003A interfaces to a link aggregation trunk. The FortiSwitch-5003A board uses a hash algorithm based on source and destination IP addresses to distribute sessions to the interfaces added to the trunk. Each interface in the trunk usually corresponds to a slot in the chassis in which a FortiGate-5001A or 5005FA2 board is installed. You can also include FortiSwitch-5003A front panel interfaces in a trunk and distribute sessions to FortiGate-5000 boards installed in multiple chassis.

Note: The FortiSwitch-5003A board does not support Link Aggregation Control Protocol (LACP). LACP is also called 802.3ad dynamic mode layer-2 link aggregation.

You can add up to 8 interfaces to a trunk to distribute sessions among up to 8 FortiGate-5000 boards. You can also add multiple trunks to a single FortiSwitch-5003A board. The total number of FortiGate-5000 boards in a trunk is limited by the amount of bandwidth you are processing and the capacity of the FortiSwitch-5003A board. Fortinet does not support mixing FortiGate-5001A and 5005FA2 boards in the same trunk.

If you add a FortiGate-5000 board to a trunk, or if you remove a FortiGate-5000 board from a trunk the link aggregation hash algorithm recalculates the session distribution. If the FortiSwitch-5003A system is processing traffic when you add or remove a FortiGate-5000 board, after sessions are redistributed the FortiGate-5000 boards in the trunk will not necessarily continue to process the same sessions. The same happens if a FortiGate-5000 board in a trunk fails. The FortiSwitch-5003A system does not maintain a session table, so changes to a trunk can result in communication being temporarily interrupted. As a result you should only add or remove FortiGate-5000 boards from a trunk during off-peak hours.

The FortiGate-5000 boards in a trunk must operate in transparent mode. All the FortiGate-5000 boards in a trunk are managed separately and all must have the same configuration. You can use the FortiManager system to maintain the same configuration on the FortiGate-5000 boards.

 

FortiSwitch-5003A and 5003 Fabric and Base Backplane Communications Guide

56

01-30000-85717-20081205

Page 56
Image 56
Fortinet 5003A manual Fabric channel layer-2 link aggregation

5003, 5003A specifications

Fortinet's FortiGate 5003 and 5003A are high-capacity, next-generation firewalls designed for enterprises that require advanced security solutions with a strong focus on performance and scalability. These models are part of Fortinet's expansive line of FortiGate appliances, which leverage innovative technologies to provide robust protection against a variety of cyber threats while maintaining seamless network operations.

One of the standout features of the FortiGate 5003 and 5003A is their impressive throughput capabilities. With multiple high-speed network interfaces, these firewalls can handle substantial amounts of traffic, ensuring that data flows smoothly without creating bottlenecks. This makes them ideal for organizations that operate large-scale networks or have significant bandwidth demands.

The FortiGate 5003 series is equipped with Fortinet's proprietary FortiOS, an intuitive operating system that integrates firewall, VPN, antivirus, intrusion prevention, web filtering, and application control functionalities. This comprehensive approach to security allows organizations to protect their networks from an array of cyber threats while simplifying management and reducing operational costs.

Another key characteristic of these models is their use of Fortinet's purpose-built security processing units (SPUs). These hardware-accelerated security chips enable accelerated threat detection and prevention, allowing the 5003 and 5003A to deliver high performance even when advanced security features are enabled. The SPUs play a crucial role in ensuring that organizations can enforce security policies without compromising on speed or efficiency.

Furthermore, the FortiGate 5003 and 5003A support advanced networking features, including Virtual Routing and Forwarding (VRF), which allows for better traffic management and segmentation. This capability is essential in multi-tenant environments, enabling organizations to create isolated networks while maintaining centralized security management.

In addition to their performance and feature set, both models support centralized management through Fortinet's FortiManager platform, providing a unified view of network security across multiple devices. This simplifies configuration, updates, and policy compliance, significantly reducing administrative overhead.

Finally, the FortiGate 5003 and 5003A are designed with redundancy and high availability in mind. They include failover capabilities and support for clustering, ensuring that network operations remain uninterrupted even in the event of hardware failure. This level of reliability is vital for mission-critical applications where downtime can lead to significant operational disruption.

In summary, Fortinet's FortiGate 5003 and 5003A are powerful solutions that combine high performance, advanced security technologies, and robust management features to meet the needs of large enterprises. With their focus on scalability and reliability, these firewalls are poised to protect organizations against evolving cyber threats while ensuring optimal network performance.