Technical Tip: HA Failover issues with layer-3 switches
| Description | This article explains potential issues that may occur when operating FortiGate clusters in High Availability (HA) mode with third-party Layer-3 switches. |
| Scope | FortiGate v7.0 and above. Operating in High Availability (HA) mode. |
| Solution | During an HA failover event, the newly elected primary FortiGate unit sends special ARP packets to update the MAC address forwarding tables of directly connected switches.
When using Layer-2 switches:
When using Layer-3 switches:
Layer-3 switches maintain a cache of IP-to-interface mappings that do not get refreshed by ARP updates alone.
Possible solution: Manually clear or flush the forwarding (ARP or routing) table on the Layer-3 switch after a failover to force it to learn the new path.
Note: For the failure signal, enable the following command:
config system ha
Related article: Troubleshooting Tip: FortiGate HA link-failed-signal and switching MAC address tables |
