Dears , We need your support to make a HA connection between MS452 core switch to Fortigate 1000D firewall, we tried to connect 10Gb SFP in Meraki side and 1Gb SFP in FIrewall but the port not come online, Already both Core switch in STACK, how can we get the redundant link incase of switch 1 or switch 2 failure. Please find the attached below STACK image , we need to connect like below, and Port configuration also shared below,
switch1 - Port 29 --> Firewall 1
switch1 - Port 31 --> Firewall 2
switch2 - Port 29 --> Firewall 1
switch2 - Port 31 --> Firewall 2
The SFPs on both sides have to match. You should use 10G SFP+ on both sides of the link.
Hi Karstenl, But the Fortigate only support 1Gb,
@Raffick Then you need 1Gb SFP modules in the MS425 or if you have a dual speed module then you might be able to set it to forced 1000Mb
@Raffick wrote:Hi Karstenl, But the Fortigate only support 1Gb,
Is it really a 1000D? That one supports 10Gig with SFP+ modules.
Yes , Fortigate have 2 10Gb port, but here the challenge is its not support aggregate between two 10Gb port, I need to connect 2 connection from core 1 and core 2 to Firewall,
@Raffick You need to mathc SFP module speed at each each as already mentioned. If the Fortigate doesn't support link aggreation on its 10Gb ports then you will need to use a 1Gb port.
@Raffick, once you’ve replaced the SFP+ modules with SFP and got your links working at 1Gbps, you might want to create an aggregation port too. Select port 29 from both switches and create and aggregation, and likewise for port 31, so you end up with two logical links. On the FortiGates you also create aggregation ports, two ports on Firewall 1, and then two ports on Firewall 2.
@Raffick : It is important to understand that you need to match the SFP or SFP+ on both side.