question

stylus avatar image
0 Likes"
stylus asked

Link aggregation balancing question

There are 3 different modes on the FortiGate to balance the load on Link Aggregation ports.

set algorithm
L2    Use layer 2 address for distribution.
L3    Use layer 3 address for distribution.
L4    Use layer 4 information for distribution.


L2 is using SMAC/DMAC
L3 is using SIP/DIP
L4 is using SPORT/DPORT/PROTO

But the debug command to calculate the port to be selected also considers other options.

diagnose netlink aggregate port
<aggregate-interface> [ src-mac <mac-addr> ] [ dst-mac <mac-addr> ] [ src-ip <IPv4-addr> ] [ dst-ip <IPv4-addr> ] [ proto <IP-protocol> ] [ src-port <TCP/UDP port> ] [ dst-port <TCP/UDP port> ] [ vlan-id <VLAN-Id> ] [ spi <IPsec-SPI> ] [ frag (offset|flag) ]

Can VLAN ID, SPI be criteria to select the port? Let's put it this way: if I have a single IPSec tunnel over LACP, creating multiple SAs under it, will it allow me to split the traffic among LACP members?

FortiOSPort
10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

0 Answers

·

Write an Answer

Hint: Notify or tag a user in this post by typing @username.

Up to 10 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

Welcome to FortiAnswers

FortiAnswers is the space dedicated to FortiSASE and FortiOS questions and suggestions.

  • Please review the Community guidelines
  • If you are a moderator, please refer to the Moderation guidelines
  • If something in the above guidelines is unclear, please post your question to the Community Feedback space or the Moderators' space