interface
Use this command to edit the configuration of a FortiAnalyzer network interface.
Syntax
To configure a physical interface:
config system interface
edit <interface name>
set status {enable | disable}
set mode {dhcp | static}
set ip <ipv4_mask>
set dhcp-client-identifier <integer>
set defaultgw {enable | disable}
set dns-server-override {enable | disable}
set mtu-override {enable | disable}
set allowaccess {fgfm http https https-logging ping snmp soc-fabric ssh webservice}
set lldp {enable | disable}
set speed {1000full | 100full | 100half | 10full | 10half | auto}
set description <string>
set alias <string>
set mtu <integer>
set type {aggregate | physical | vlan}
config ipv6
set ip6-address <ipv6 prefix>
set ip6-allowaccess {fgfm http https https-logging ping snmp ssh webservice}
set ip6-autoconf {enable | disable}
end
end
To configure an aggregate interface:
config system interface
edit <interface name>
set status {enable | disable}
set mode {dhcp | static}
set ip <ipv4_mask>
set dhcp-client-identifier <integer>
set defaultgw {enable | disable}
set dns-server-override {enable | disable}
set mtu-override {enable | disable}
set allowaccess {fgfm http https https-logging ping snmp soc-fabric ssh webservice}
set speed {1000full | 100full | 100half | 10full | 10half | auto}
set description <string>
set alias <string>
set mtu <integer>
set type {aggregate | physical | vlan}
set lacp-speed {fast | slow}
set min-links <integer>
set min-links-down {administrative | operational}
set link-up-delay <integer>
config member
edit <interface-name>
end
config ipv6
set ip6-address <ipv6 prefix>
set ip6-allowaccess {fgfm http https https-logging ping snmp ssh webservice}
set ip6-autoconf {enable | disable}
end
end
To configure a VLAN interface:
config system interface
edit <interface name>
set status {enable | disable}
set mode {dhcp | static}
set ip <ipv4_mask>
set dhcp-client-identifier <integer>
set defaultgw {enable | disable}
set dns-server-override {enable | disable}
set mtu-override {enable | disable}
set allowaccess {fgfm http https https-logging ping snmp soc-fabric ssh webservice}
set speed {1000full | 100full | 100half | 10full | 10half | auto}
set description <string>
set alias <string>
set mtu <integer>
set type {aggregate | physical | vlan}
set interface <string>
set vlanid <integer>
set vlan-protocol {8021ad | 8021q}
config ipv6
set ip6-address <ipv6 prefix>
set ip6-allowaccess {fgfm http https https-logging ping snmp ssh webservice}
set ip6-autoconf {enable | disable}
end
end
Variable |
Description |
---|---|
<interface name> |
The interface name. The port can be set to a port number such as |
status {enable | disable} |
Enable/disable the interface (default = enable). If the interface is disabled it does not accept or send packets. If you disable a physical interface, VLAN interfaces associated with it are also disabled. |
mode {dhcp | static} |
Set the addressing mode (static setting, or DHCP client mode). |
ip <ipv4_mask> |
Enter the interface IPv4 address and netmask. The IPv4 address cannot be on the same subnet as any other interface. |
dhcp-client-identifier <integer> |
Enter the DHCP client identifier (default = (null)). This variable is only available when the |
defaultgw {enable | disable} |
Enable/disable default gateway (default = enable). This variable is only available when the |
dns-server-override {enable | disable} |
Enable/disable use DNS acquired by DHCP or PPPoE (default = enable). This variable is only available when the |
mtu-override {enable | disable} |
Enable/disable use MTU acquired by DHCP or PPPoE (default = enable). This variable is only available when the |
allowaccess {fgfm http https https-logging ping snmp soc-fabric ssh webservice} |
Enter the types of management access permitted on this interface. Separate multiple selected types with spaces. If you want to add or remove an option from the list, retype the list as required. |
lldp {enable | disable} |
Enable or disable the link layer discovery protocol (LLDP) (default = disable). This variable is only available when the |
speed {1000full | 100full | 100half | 10full | 10half | auto} |
Enter the speed and duplexing the network port uses:
|
description <string> |
Enter a description of the interface (character limit = 63). |
alias <string> |
Enter an alias for the interface. |
mtu <integer> |
Set the maximum transportation unit (68 - 9000, default = 1500). |
type {aggregate | physical | vlan} |
Set the type of interface (default = aggregate). |
lacp-speed {fast | slow} |
Set how often the interface sends LACP messages:
This variable is only available when the |
min-links <integer> |
Set the minimum number of aggregated ports that must be up (default = 1). This variable is only available when the |
min-links-down {administrative | operational} |
Action to take when less than the configured minimum number of links are active:
This variable is only available when the |
link-up-delay <integer> |
Set the number of milliseconds to wait before considering a link is up (default = 50). This variable is only available when the |
interface <string> |
Set the underlying interface name for the VLAN interface. This variable is only available when the |
vlanid <integer> |
Set the VLAN ID (1 - 4094, default = 0). This variable is only available when the |
vlan-protocol {8021ad | 8021q} |
Set the ethernet protocol of the VLAN (IEEE 802.1AD or IEEE 802.1Q, default = IEEE 802.1Q). This variable is only available when the |
Variables for This subcommand is only available when the |
|
<interface-name> |
Enter the interface name that belongs to the aggregate or the redundant interface. |
Variables for |
|
ip6-address <ipv6 prefix> |
IPv6 address/prefix of interface. |
ip6-allowaccess {fgfm http https https-logging ping snmp ssh webservice} |
Allow management access to the interface. |
ip6-autoconf {enable | disable} |
Enable/disable address automatic configuration (SLAAC) (default = enable). |
Example
This example shows how to set the FortiAnalyzer port1 interface IPv4 address and network mask to 192.168.100.159
and 255.255.255.0
, and the management access to ping
, https
, and ssh
.
config system interface
edit port1
set allowaccess ping https ssh
set ip 192.168.110.26 255.255.255.0
set status enable
end