Troubleshooting Tip: SFP module port flap OR port not coming UP due to module being in ERROR state
Description
This article describes the probable cause and fixes for the FortiSwitch 'Module in ERROR state' error.
Scope
FortiSwitch version 6.4.x and above.
- FortiSwitch SFP/SFP+ port may not come up OR the port will keep flapping UP and down.
- FortiSwitch may report high CPU usage.
Solution
- '# get switch modules status' and ' # get switch modules summary' command outputs may show 'Module in ERROR state', as shown in the following CLI output:
# get switch modules statusPort(port5)
Module in ERROR state
# get switch modules summary
Portname State Type Transceiver RX Vendor Part Number Serial Number
__________ _______ _______ ____________ ___ ________________
port5 ERROR
port6 ERROR
- This error may also increase FortiSwitch CPU usage due to the 'Diagnostic Monitoring Interface (DMI)' ('dmid') process:
get system performance status
CPU states: 1% user 66% system 0% nice 43% idle
Memory states: 11% used
Average network usage: 0 kbps in 1 minute, 0 kbps in 10 minutes, 0 kbps in 30 minutes
Uptime: 15 days, 10 hours, 29 minutes
get system performance top
Run Time: 15 days, 10 hours and 29 minutes
0U, 57S, 43I; 2023T, 1712F
dmid 1858 R 97.0 0.5 ---------------- > dmid
igmpsnoopingd 1822 R N 1.9 0.7
ctrld 1851 S 1.9 0.5
lfgd 1820 S 1.9 0.5
lldpmedd 1857 S 0.9 0.7
- To overcome the FortiSwitch 'Module in ERROR state' error – use a supported FortiSwitch Transceiver suitable for the FortiSwitch Model. Refer to the following link for a FortiSwitch Compatible Transceivers list:
Compatible transceivers - FortiSwitch documentation.
- Check the logs on the FortiSwitch with the following command:
execute log filter view-lines 1000
execute log display
Open the logs in a notepad file and search for any logs related to the port#. You may find below errors on the SFP ports:-
15: 2021-08-10 14:30:47 log_id=0100001050 type=event subtype=link pri=warning vd=root action="physical-port-change" user="dmid" status="None" switch.physical-port="port28" msg="port28, failed BASE ID Check Sequence"
This error is fixed in FortiSwitch versions 6.4.11, 7.0.4, 7.2.0 and above.
Note: For an updated FortiSwitch Compatible Transceivers list, visit FortiSwitch hardware - Fortinet products.
- In some circumstances, the error above can be also resolved by powering down the switch for about 10 to 15 minutes to allow internal circuits to drain power from capacitors.
Once the switch is powered up, its ports with SFP modules will show them as operable:
get switch module summary
Portname State Type DMI Transceiver RX Vendor Part Number Serial Number
_________ _______ _______ ___ ____________ ___ ________________ ________________
port25 INSERT SFP/SFP+ N 10G-Base-CR* OK CISCO-TYCO 1-2053783-1 TED1550A6P7
port26 ALARM SFP/SFP+ Y 10G-Base-SR LOS OEM TR-SFP-10G-SR HO23C0913251
port27 EMPTY
port28 ALARM SFP/SFP+ Y 10G-Base-LR LOS OEM XZS-SFP10G-LR C23Y32WS05218
port29.1 INSERT QSFP+ Y 40G-Base-SR4 N/A +Fortinet FTL410QE4CFTN U8NBXPX
port29.2 INSERT QSFP+ Y 40G-Base-SR4 N/A +Fortinet FTL410QE4CFTN U8NBXPX
port29.3 INSERT QSFP+ Y 40G-Base-SR4 N/A +Fortinet FTL410QE4CFTN U8NBXPX
port29.4 INSERT QSFP+ Y 40G-Base-SR4 N/A +Fortinet FTL410QE4CFTN U8NBXPX
port30.1 ALARM QSFP+ Y 40G-Base-SR4 N/A +Fortinet FTL410QE4CFTN U8NBXQK
port30.2 ALARM QSFP+ Y 40G-Base-SR4 N/A +Fortinet FTL410QE4CFTN U8NBXQK
port30.3 ALARM QSFP+ Y 40G-Base-SR4 N/A +Fortinet FTL410QE4CFTN U8NBXQK
port30.4 ALARM QSFP+ Y 40G-Base-SR4 N/A +Fortinet FTL410QE4CFTN U8NBXQK
- If the above step does not resolve the issue, contact Fortinet Support and attach the following data for analysis.
- FortiSwitch Model.
- Transceiver Make and Model:
- Verify whether the Transceiver model is supported on FortiSwitch Model (refer to the FortiSwitch Compatible Transceivers list).
- Attach the following logs from FortiSwitch:
show full
diag debug report
diagnose switch modules state-machine
get switch modules detail
get switch modules summary
get switch modules status
Related articles:
- Troubleshooting Tip: SFP/SFP+ transceivers port/fiber link is not coming up
- Technical Tip: Recommended Port speed configuration for SR (short range) SFP cable
- Technical Tip: Recommended port speed configuration when using copper SFP module 1000-Base-T
- Technical Tip: Recommended port speed configuration for SFP module 1000-Base-SX and 1000-Base-LX
- Technical Tip: Port speed configuration for DAC (Direct Attach Copper) cable
