Skip to main content
riteshpv
Staff
Staff
April 1, 2026

Technical Tip: Proxy ARP is not working across FortiSwitch MRP ring in FortiLink

  • April 1, 2026
  • 0 replies
  • 200 views
Description This article describes an issue where Proxy ARP does not function when devices are connected to downstream FortiSwitches that do not have a direct connection to the FortiGate in a FortiLink topology.
Scope FortiGate and FortiSwitch v7.4, v7.6 in FortiLink mode.
Solution

The following features are configured in the FortiLink setup:

Appendix A: Configuring the Media Redundancy Protocol 
Blocking intra-VLAN traffic 


Observation: 

When both features are enabled:

  • Blocking intra-VLAN traffic operates partially for devices connected to Tier-1 FortiSwitches (directly connected to FortiGate).
  • Devices connected to downstream FortiSwitches (below Tier-1) do not behave as expected, and Proxy ARP functionality is affected.


Reason:

Media Redundancy Protocol (MRP) and blocking intra-VLAN traffic are not interoperable and do not function correctly when enabled together in the same topology.

 

Solutions:

  • If Media Redundancy Protocol (MRP) is required, blocking intra-VLAN traffic must not be enabled.
  • If blocking intra-VLAN traffic is required, Media Redundancy Protocol (MRP) must not be used.