Fortinet 5003 User Manual

Page 25

Advertising
background image

FortiGate-5140 fabric backplane communication

Fabric gigabit switching within a chassis

FortiSwitch-5003A and 5003 Fabric and Base Backplane Communications Guide
01-30000-85717-20081205

25

The chassis can be connected to the network using any of the FortiGate-5001A
front panel interfaces. You can also connect FortiSwitch-5003A front panel fabric
interfaces to the network. You can also install FortiGate AMC modules in the
FortiGate-5001A boards and connect the network to the AMC front panel
interfaces. The AMC modules and the network connections are not shown in

Figure 9

.

For the FortiGate-5001A boards to use the fabric channel 1 for data
communication you must show backplane interfaces on the FortiGate-5001A
web-based manager and then configure firewall polices and routing for the fabric1
interfaces.

If the data traffic contains VLAN-tagged packets, you must add the VLAN tags to
the FortiSwitch-5003A interfaces that will handle the VLAN-tagged traffic. For
example, to allow VLAN tags 201 to 210 on slots 9, 11, and 13 from the
FortiSwitch-5003A CLI enter:

config switch fabric-channel interface

edit "slot-9"

set allowed-vlans 1,201-210

next
edit "slot-11"

set allowed-vlans 1,201-210

next
edit "slot-13"

set allowed-vlans 1,201-210

end

For more information about the FortiSwitch-5003A CLI, see

“FortiSwitch-5003A

CLI reference” on page 89

.

Figure 10

shows a FortiGate-5140 chassis with FortiSwitch-5003A boards in

hub/switch slots 1 and 2 and FortiGate-5001A and 5005FA2 boards in all of the
other slots. The FortiGate boards can use fabric channels 1 and 2 for data
communication among the FortiGate boards. In this configuration the
FortiSwitch-5003A boards are operating as layer-2 switches for fabric channels 1
and 2 and the FortiGate boards are operating as typical standalone FortiGate
units.

The chassis can be connected to the network using any of the FortiGate front
panel interfaces. You can also connect FortiSwitch-5003A front panel fabric
interfaces to the network. You can also install FortiGate AMC modules in the
FortiGate-5001A boards and connect the network to the AMC front panel
interfaces. The AMC modules and the network connections are not shown in

Figure 10

.

Advertising