Interfaces
System Network
FortiGate Version 4.0 Administration Guide
136
01-400-89802-20090424
FortiGate models numbered 3 000 and higher support jumbo frames - frames larger than
the traditional 1 500 bytes. Some models support a jumbo frame limit of 9 000 bytes while
others support 16 110 bytes. NP2-accelerated interfaces support a jumbo frame limit of
16 000 bytes. FA2-accelerated interfaces do not support jumbo frames. Jumbo frames are
much larger than the maximum standard Ethernet frames (packets) size of 1 500 bytes.
As new Ethernet standards have been implemented (such as Gigabit Ethernet), 1 500
byte frames remain in the standard for backward compatibility.
To be able to send jumbo frames over a route, all Ethernet devices on that route must
support jumbo frames, otherwise your jumbo frames are not recognized and are dropped.
If you have standard ethernet and jumbo frame traffic on the same interface, routing alone
cannot route them to different routes based only on frame size. However you can use
VLANs to make sure the jumbo frame traffic is routed over network devices that support
jumbo frames. VLANs will inherit the MTU size from the parent interface. You will need to
configure the VLAN to include both ends of the route as well as all switches and routers
along the route. For more information on VLAN configurations, see the
To change the MTU size of the packets leaving an interface
1
Go to
System > Network > Interface
.
2
Choose a physical interface and select
Edit
.
3
Below
Administrative Access
, select
Override default MTU value (1 500)
.
4
Set the MTU size.
If you select an MTU size larger than your FortiGate unit supports, an error message
will indicate this. In this situation, try a smaller MTU size until the value is supported.
Supported maximums are 16 110, 9 000, and 1 500.
See also
Secondary IP Addresses
An interface can be assigned more than one IP address. You can create and apply
separate firewall policies for each IP address on an interface. You can also forward traffic
and use RIP or OSPF routing with secondary IP addresses.
There can be up to 32 secondary IP addresses per interface including primary, secondary,
and any other IP addresses assigned to the interface. Primary and secondary IP
addresses can share the same ping generator.
The following restrictions must be in place before you are able to assign a secondary IP
address:
•
A primary IP address must be assigned to the interface.
•
The interface must use manual addressing mode.
•
By default, IP addresses cannot be part of the same subnet. To allow interface subnet
overlap use the CLI command:
Note:
If you change the MTU, you need to reboot the FortiGate unit to update the MTU
value of VLAN subinterfaces on the modified interface.
Note:
In Transparent mode, if you change the MTU of an interface, you must change the
MTU of all interfaces to match the new MTU.
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...