12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

System Network<br />

Interface<br />

Use secure administrative user passwords.<br />

Change these passwords regularly.<br />

Enable secure administrative access to this interface using only HTTPS or SSH.<br />

Do not change the system idle timeout from the default value of 5 minutes (see<br />

“Settings” on page 175).<br />

For more information on configuring administrative access in Transparent mode,<br />

see “Operation mode and VDOM management access” on page 158.<br />

To control administrative access to an interface<br />

1 Go to System > Network > Interface.<br />

2 Choose an interface and select Edit.<br />

3 Select the Administrative Access methods for the interface.<br />

4 Select OK to save the changes.<br />

Interface MTU packet size<br />

To improve network performance, you can change the maximum transmission unit<br />

(MTU) of the packets that the <strong>FortiGate</strong> unit transmits. Ideally, the MTU should be<br />

the same as the smallest MTU of all the networks between the <strong>FortiGate</strong> unit and<br />

the destination of the packets. If the packets that the <strong>FortiGate</strong> unit sends are<br />

larger, they are broken up or fragmented, which slows down transmission.<br />

Experiment by lowering the MTU to find an MTU size for best network<br />

performance.<br />

<strong>FortiGate</strong> models numbered 3000 and higher support jumbo frames. Some<br />

models support a limit of 9 000 bytes while others support 16 110 bytes. Jumbo<br />

frames can be up to 9 000 bytes or 16110, much larger than standard Ethernet<br />

frames. Standard Ethernet frames (packets) can be a maximum of 1 500 bytes<br />

including header information. As new Ethernet standards have been implemented<br />

(such as Gigabit Ethernet), 1 500-byte frames have been kept for backward<br />

<strong>com</strong>patibility.<br />

To be able to send jumbo frames over a route, all Ethernet devices on that route<br />

must support jumbo frames. Otherwise your jumbo frames are not recognized and<br />

they are dropped.<br />

If you have standard ethernet and jumbo frame traffic on the same interface,<br />

routing alone cannot route them to different routes based only on frame size.<br />

However you can use VLANs to make sure the jumbo frame traffic is routed over<br />

network devices that support jumbo frames. VLANs will inherit the MTU size from<br />

the parent interface. You will need to configure the VLAN to include both ends of<br />

the route as well as all switches and routers along the route. For more information<br />

on VLAN configurations, see the VLAN and VDOM guide.<br />

To change the MTU size of the packets leaving an interface<br />

1 Go to System > Network > Interface.<br />

2 Choose a physical interface and select Edit.<br />

3 Select Override default MTU value (1500).<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 95

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!