FortiGate 3600E and 3601E fast path architecture
The FortiGate 3600E and 3601E each include six NP6 processors (NP6_0 to NP6_5). All front panel data interfaces and all of the NP6 processors connect to the integrated switch fabric (ISF). All data traffic passes from the data interfaces through the ISF to the NP6 processors. Because of the ISF, all supported traffic passing between any two data interfaces can be offloaded by the NP6 processors. No special mapping is required for fast path offloading or aggregate interfaces. Data traffic processed by the CPU takes a dedicated data path through the ISF and an NP6 processor to the CPU.
The FortiGate 3600E and 3601E models feature the following front panel interfaces:
- Two 10/100/1000BASE-T Copper (MGMT1 and MGMT2)
- Two 10/25 GigE SFP+/SFP28 (HA1 and HA2, not connected to the NP6 processors)
- Thirty 10/25 GigE SFP+/SFP28 (1 to 30) interface groups: HA1 - HA2 - 1 - 2, 3 - 6, 7 - 10, 11 - 14, 15 - 18, 19 - 22, 23 - 26, and 27 - 30. Every time you change the speed of one of these interfaces from 25Gbps to 10Gbps or 1Gbps or from 10Gbps or 1Gbps to 25Gbps the speeds of the other interfaces in the group also change to that speed. When you enter the
end
command, the CLI confirms the range of interfaces affected by the change. - Six 100 GigE QSFP28 (31 to 36)
The FortiGate-3600 and 3601 do not support auto-negotiation when setting interface speeds. Always set a specific interface speed. For example: config system interface edit port31 set speed {40000full | 100Gfull} end |
The MGMT interfaces are not connected to the NP6 processors. Management traffic passes to the CPU over a dedicated management path that is separate from the data path. You can also dedicate separate CPU resources for management traffic to further isolate management processing from data processing (see Dedicated management CPU).
The HA interfaces are also not connected to the NP6 processors. To help provide better HA stability and resiliency, the HA traffic uses a dedicated physical control path that provides HA control traffic separation from data traffic processing.
The separation of management and HA traffic from data traffic keeps management and HA traffic from affecting the stability and performance of data traffic processing.
You can use the following command to display the FortiGate 3600E or 3601E NP6 configuration. You can also use the diagnose npu np6 port-list
command to display this information.
get hardware npu np6 port-list Chip XAUI Ports Max Cross-chip Speed offloading -------------------- ---- ------ ------- ---------- NP#0-5 0-3 port1 25000M Yes NP#0-5 0-3 port2 25000M Yes NP#0-5 0-3 port3 25000M Yes NP#0-5 0-3 port4 25000M Yes NP#0-5 0-3 port5 25000M Yes NP#0-5 0-3 port6 25000M Yes NP#0-5 0-3 port7 25000M Yes NP#0-5 0-3 port8 25000M Yes NP#0-5 0-3 port9 25000M Yes NP#0-5 0-3 port10 25000M Yes NP#0-5 0-3 port11 25000M Yes NP#0-5 0-3 port12 25000M Yes NP#0-5 0-3 port13 25000M Yes NP#0-5 0-3 port14 25000M Yes NP#0-5 0-3 port15 25000M Yes NP#0-5 0-3 port16 25000M Yes NP#0-5 0-3 port17 25000M Yes NP#0-5 0-3 port18 25000M Yes NP#0-5 0-3 port19 25000M Yes NP#0-5 0-3 port20 25000M Yes NP#0-5 0-3 port21 25000M Yes NP#0-5 0-3 port22 25000M Yes NP#0-5 0-3 port23 25000M Yes NP#0-5 0-3 port24 25000M Yes NP#0-5 0-3 port25 25000M Yes NP#0-5 0-3 port26 25000M Yes NP#0-5 0-3 port27 25000M Yes NP#0-5 0-3 port28 25000M Yes NP#0-5 0-3 port29 25000M Yes NP#0-5 0-3 port30 25000M Yes NP#0-5 0-3 port31 100000M Yes NP#0-5 0-3 port32 100000M Yes NP#0-5 0-3 port33 100000M Yes NP#0-5 0-3 port34 100000M Yes NP#0-5 0-3 port35 100000M Yes NP#0-5 0-3 port36 100000M Yes -------------------- ---- ------ ------- ----------