Page 1
FortiGate-5140B Chassis Guide This FortiGate-5140B Chassis Guide describes FortiGate-5140B hardware features as well as how to install a FortiGate-5140B chassis. The most recent versions of this and all FortiGate-5000 series documents are available from the FortiGate-5000 page of Fortinet Technical Documentation web site (http://docs.fortinet.com).
ESD connector such as the ESD sockets provided on FortiGate-5000 series chassis. • Make sure all FortiGate-5000 series components have reliable grounding. Fortinet recommends direct connections to the building ground. • If you install a FortiGate-5000 series component in a closed or multi-unit rack assembly, the operating ambient temperature of the rack environment may be greater than room ambient.
Page 3
• Unambiguous reference to service documentation for instructions for replacement of fuses replaceable only by service personnel. • The FortiGate-5140B chassis is capable of operating -40 VDC to -60 VDC at a maximum current level 100 A. • Caution: Double pole fusing.
If all 14 slots contain FortiGate-5001D boards, the FortiGate-5140B chassis provides a total of 28 40-gigabit ethernet interfaces. You can also install FortiSwitch-5003B boards in FortiGate-5140B chassis slots 1 and 2 to provide base backplane communications using the dual star 1-gigabit base backplane interface.
Finally, you can add other Fortinet 5000 series boards to a FortiGate-5140B chassis, including the 5000 series FortiMail and FortiManager boards. Some of the boards installed in a FortiGate-5140B chassis can be operating in a FortiGate HA cluster and some can be operating as standalone FortiGate units. You can also operate multiple HA clusters and standalone FortiGate units in a single FortiGate-5140B chassis.
Page 11
• Chassis handles. Do not operate the FortiGate-5140B chassis with open slots on the front panel. For optimum cooling performance and safety, the chassis slots must contain a FortiGate-5000 series board or an air baffle slot filler. For the same reason, all cooling fan trays and the air filter should be installed while operating the chassis.
Figure 2 shows the back of a FortiGate-5140B chassis. The FortiGate-5140B chassis back panel includes two redundant -48V to - 60 VDC power entry modules (PEMs). Fortinet ships the FortiGate-5140B chassis with both installed. The PEMs provide redundant DC power connections for the FortiGate-5140B chassis and distribute DC power to all chassis slots and components.
• FortiGate RTM-XB2 Power requirements The FortiGate-5140B chassis is designed to be installed in a data center or similar location that has available -48VDC power fed from a 100A listed circuit breaker (also called battery power or main DC power). Fortinet expects that most FortiGate-5140B...
PSU-5000B power supplies to convert AC to DC to supply DC power to the FortiGate-5140B chassis from an AC source. Physical description of the FortiGate-5140B chassis The FortiGate-5140B chassis is a 13U chassis that can be installed in a standard 19-inch rack. Table 1 describes the physical characteristics of the FortiGate-5140B chassis.
Page 15
The hot swap LED starts blinking blue. When the hot swap LED turns solid blue you can completely loosen both retention screws and remove the shelf manager from the chassis. Figure 3: FortiGate-5140B shelf manager front panel Ethernet CH0 network activity LEDs...
The FortiGate-5140B shelf managers monitor the internal temperature of the FortiGate-5140B chassis and adjust the operating speed of the cooling fans as required. When the chassis is first powered on all cooling fans run at full speed. Once the shelf manager is up and running, the shelf manager reduces cooling fan speeds to maintain an optimum temperature in the chassis.
Page 17
The cable required to connect to the alarm interface is not supplied by Fortinet. To monitor alarms you should connect to the telco alarm interface of the active shelf alarm panel, which by default is the one on the left.
FortiGate-5140B shelf alarm module FortiGate-5140B chassis Figure 5 shows the connections between the primary and secondary shelf managers and the shelf alarm panel. Figure 5: Ethernet connections between shelf managers and the base backplane interfaces Shelf Shelf Manager Manager (active)
Power COM Air filter The FortiGate-5140B chassis includes a front replaceable air filter that removes dust from intake air and provides static pressure to achieve uniform airflow. The filter must be installed for the chassis to operate normally. If the air filter is not locked into place the redundant air filter presence sensors cause an alarm.
Page 20
You do not need to press a hot swap switch to remove a fan. Just pull it out of the fan cabinet. The shelf manager regulates the fan speed by adjusting the DC voltage supplied to the fan trays. Table 5: FortiGate-5140B fan tray LEDs Description HS (Hot Swap) Normally off.
DC power system. If DC power is not available at the location in which the FortiGate-5140B chassis is to be installed you can use the FortiGate-5053B power converter shelf to convert AC to DC to supply DC power to the FortiGate-5140B chassis.
530W + (300W * 14) = 4730W Connecting the FortiGate-5140B chassis to DC power and ground Connect the FortiGate-5140B chassis to DC power using the redundant -48V to - 60 VDC power entry modules (PEMs) at the bottom of the chassis back panel. The specified voltage range of the PEMs is -40 VDC to -72 VDC.
If for any reason any of the PEM terminals are not used the unused terminals need to be covered with insulated material (or wrapped with electrical tape) as the exposed terminals are a shock hazard. Figure 8: Connecting a FortiGate-5140B PEM to DC power DC Power Source DC Power Source...
Page 24
3 Remove the first set of nuts and lock washers from both connectors on the PEM. 4 Connect two black -48V power wires from the DC power source to the connectors on the FortiGate-5140B PEM labeled - (the connectors on the right side of the PEM) using the double-hole lugs (see Figure Install each double-hole lug vertically.
Connecting the FortiGate-5140B chassis to ground 5 Connect two red RTN power wires from your location’s RTN terminal to the connectors on the FortiGate-5140B PEM labeled + (the connectors on the left side of the PEM) using the double-hole lug (see Figure Install each double-hole lug vertically.
Black for -48VDC and red for RTN. These cables should only be used to connect the FortiGate-5140B PEMs to a FortiGate-5053B power supply shelf if purchased with your FortiGate-5140B chassis. The double-hole lugs to be connected to the FortiGate-5140B PEMs include rubber boots that should be installed before energizing the power system.
PEM and include two or three power supplies. Example: power for a fully-loaded chassis (14 boards) The power requirement for a fully loaded FortiGate-5140B chassis with boards in all 14 slots would be: 530 W + (300 W * 14) = 4730 W If you are using high-line AC power, one PSU-5000B produces 2725W.
Connecting a FortiGate-5140B chassis to the FortiGate-5053B power supply shelf To use a FortiGate-5053B power supply shelf with the FortiGate-5140B chassis you need to make DC power connections between A FortiGate-5140B PEM and the FortiGate-5053B power supply shelf. You also need to the connect the FortiGate-5140B chassis and the FortiGate-5053B power supply shelf to ground.
Page 29
Install each double-hole lug vertically. Do not apply torque of more than 3.8 Nm (33.62 lbf.in). 10 Connect two red RTN power wires from the power supply shelf to the connectors on the FortiGate-5140B PEM labeled + (the connectors on the left side of the PEM) using the double-hole lug (see Figure 11).
If you are using local DC power, turn on the power to the chassis according to the requirements of your local DC power system. Once the FortiGate-5140B chassis is connected to DC power the chassis powers up. If the chassis is operating correctly, the LEDs on the connected PEM(s) and fans should be lit.
Make sure the operating ambient temperature does not exceed the manufacturer's maximum rated ambient temperature. The FortiGate-5140B chassis should not be operated as a free-standing appliance. Install the FortiGate-5140B chassis at the lower positions in the rack to avoid making the rack top-heavy and potentially falling over. Air flow For rack installation, make sure that the amount of air flow required for safe operation of the FortiGate-5140B chassis is not compromised.
(ESD) preventive wrist strap when handling FortiGate-5000 series or FortiSwitch-5000 series modules. Do not operate the FortiGate-5140B chassis with open slots on the front panel or rear panel. For optimum cooling performance and safety, front panel slots must contain a FortiGate-5000 series module or an air baffle slot filler and rear panel slots must either be covered or must contain a rear transition module or slot filler.
Using FortiSwitch-5203B boards for content clustering FortiSwitch-5003B boards installed in a FortiGate-5140B chassis in slot 1 or slot 2 can be combined with FortiGate-5001B boards installed in slots 3 and up to provide a content clustering configuration. See the FortiSwitch-5203B Security System Guide (supplied with your FortiSwitch-5203B board) for information about how to configure and operate a content cluster.
When you log into the shelf manager CLI you are logging into a Linux shell as root. You can begin entering commands at the # prompt: FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Output similar to the following appears as the shelf manager reboots: /etc/rc: hostname demo /etc/rc: Restoring password file to factory default 7 Enter the following command to add a new password for the root account: # passwd FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Pigeon Point Shelf Manager Command Line Interpreter CLI> version Pigeon Point Shelf Manager ver. 2.5.1 Pigeon Point is a trademark of Pigeon Point Systems. Copyright (c) 2002-2006 Pigeon Point Systems Build date/time: Nov 3 2006 09:43:12 All rights reserved# FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
For example, a FortiGate-5001A board with an AMC module is installed in logical slot 4, then at IPMB address 88, there will be FRU 0 (the FortiGate-5001A board) and FRU 1 (the AMC module). Table 8: FortiGate-5140B chassis component FRU names, IPMB addresses, and hardware addresses IPMB...
IPMI specification. Example of sensor type: • 01 for temperature sensor • 02 for voltage sensor • C0-FF for OEM reserved sensors (F0 is the hot swap sensor and F1 is the IPMB link sensor). FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
However, the shelfman.conf file contains the following lines: # ALLOW_CLEARING_CRITICAL_ALARM: This parameter of boolean type enables the # ability to clear the critical alarm condition without the alarm cutoff # button. Default is FALSE. ALLOW_CLEARING_CRITICAL_ALARM = FALSE FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Hot Swap State: M4 (Active), Previous: M4 (Active), Last State Change Cause: Normal State Change (0x0) Device ID String: "FG5005A" fruinfo clia fruinfo [-v] [-x]<addr> <fru_id> This command displays FRU Information in a user-friendly format. FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
# clia getlanconfig 1 3 Pigeon Point Shelf Manager Command Line Interpreter IP Address: 192.168.0.2 The following command displays the subnet mask associated with channel 1: # clia getlanconfig 1 subnet_mask Pigeon Point Shelf Manager Command Line Interpreter FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Enter the command with no parameters to display the current minimum fan level. Enter the command with an integer to set the minimum fan level. FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
You can also use the Linux command cat /tmp/messages to view shelf manager system log messages. This information can be useful for diagnosing system problems. This information can also help Fortinet Support diagnose shelf manager system problems. The sel command shows the contents of the SEL on the specified IPM Controller (at IPMB address 20h by default).
• The sensor type and event/reading type code • The Entity ID, Entity Instance of the related entity (the FRU device ID if the sensor is associated with a FRU) Example for slot 11 and sensor 13: FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Use this command to add, delete, modify and display RMCP user accounts for a shelf manager. Display all user accounts Enter the following command to display user account information: clia user -v Pigeon Point Shelf Manager Command Line Interpreter FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Page 61
Pigeon Point Shelf Manager Command Line Interpreter 1: "" Channels 0-15 Privilege level: "Administrator" Flags: "IPMI Messaging" clia user add 9 "user_1" 0x40 4 "my-password" Pigeon Point Shelf Manager Command Line Interpreter User 9 added successfuly clia user FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Page 62
Where <user_id> is the user account ID and <new_password> is the new password. For example, enter the following command to change the user name of user account 6 to NEW-password: clia user password 6 NEW-password FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
FortiSwitch-5000 series board in logical slot 1, FortiGate-5000 series boards in logical slots 6, 8, 10, and 11. The same settings will work for a FortiGate-5140, FortiGate-5060 or FortiGate-5050 chassis after making adjustments for the slot numbers. FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Page 64
1 Use the following command to set the community name used in PET traps. This can be any community name, the default is public. # clia setlanconfig 1 16 “<community_name>” For example, use the following command to set the community name to MyCommunity # clia setlanconfig 1 16 MyCommunity FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Page 65
<filter_configuration>. In this example the filter configuration is ways set to 80 to enable the filter. <filter_action>. In this example the filter action is ways set to 1 to set the action to alert. <alert_policy_number>. In this example the alert policy number is 5. FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
4 Enter the following command to restart the snmpd process: # daemon -f snmpd -c /etc/snmpd.conf 5 To confirm that the process has restarted enter the ps command again and confirm that the snmpd process is in the list. FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
The following example event log entry records that the rear fan in Fan Tray 1 (middle fan tray) is spinning below the required RPM rate. 0x018D: Event: at Jan 1 00:02:15 1970; from:(0x10,0,0); sensor:(0x04,10); event:0x1(asserted): "Upper Critical", Threshold: 0xff, Reading: 0xff FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Pigeon Point Shelf Manager Command Line Interpreter 10: FRU # 0 Entity: (0xf0, 0x60) Hot Swap State: M4 (Active), Previous: M3 (Activation In Process), Last State Change Cause: Normal State Change (0x0) Device ID String: "ShMM-500" FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Page 74
Hot Swap State: M7 (Communication Lost), Previous: M4 (Active), Last State Change Cause: Unknown (0xf) 86: Entity: (0xa0, 0x60) Maximum FRU device ID: 0x00 Hot Swap State: M7 (Communication Lost), Previous: M4 (Active), Last State Change Cause: Unknown (0xf) FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Shows a low voltage warning on the backup battery on shelf manager 1: 0x022C: Event: at Jan 1 23:09:06 2010; from:(0x10,0,0); sensor:(0x02,6); event:0x1(asserted): "Lower Critical", Threshold: 0xb3, Reading: 0x99 Shows the board in ATCA slot 4 has exceeded the incoming air temperature limit: FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
Page 86
"Upper Critical", 0x09 0xFF 0xFF Shows the board in ATCA slot 4 has exceeded the CPU board temperature limit: 0x0081: Event: at Jan 1 00:30:40 1970; from:(0x8e,0,0); sensor:(0x01,13); event:0x1(asserted): "Upper Critical", 0x09 0xFF 0xFF FortiGate-5140B Chassis Guide 01-500-156415-20151104 http://docs.fortinet.com/...
For more information Training Services Fortinet Training Services offers courses that orient you quickly to your new equipment, and certifications to verify your knowledge level. Fortinet training programs serve the needs of Fortinet customers and partners world-wide. Visit Fortinet Training Services at http://campus.training.fortinet.com, or email training@fortinet.com.
Page 88
Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied.