Cisco c2960 switches to Fotigate 400e in HA aggregation
- August 23, 2020
- 2 replies
- 5000 views
Hi, Need urgent attention with an issue related to trunking aggregated ports in criss-cross HA environment. I am sharing below configs from cisco c2960 switch1 and cisco c2960 switch 2 with on the firewall fortigate 400E with ports 9,10,11,12 in 802.3ad aggregate. Switch C2960 -1 interface GigabitEthernet1/0/33 switchport trunk native vlan 400 switchport trunk allowed vlan 2,3,11,15,18,50,52-54,62,64-66,161,171-174,181 switchport trunk allowed vlan add 400 switchport mode trunk switchport nonegotiate channel-protocol lacp channel-group 11 mode active ! interface GigabitEthernet1/0/34 switchport trunk native vlan 400 switchport trunk allowed vlan 2,3,11,15,18,50,52-54,62,64-66,161,171-174,181 switchport trunk allowed vlan add 400 switchport mode trunk switchport nonegotiate channel-protocol lacp channel-group 11 mode active ! interface GigabitEthernet1/0/35 switchport trunk native vlan 400 switchport trunk allowed vlan 2,3,11,15,18,50,52-54,62,64-66,161,171-174,181 switchport trunk allowed vlan add 400 switchport mode trunk switchport nonegotiate channel-protocol lacp channel-group 12 mode active ! interface GigabitEthernet1/0/36 switchport trunk native vlan 400 switchport trunk allowed vlan 2,3,11,15,18,50,52-54,62,64-66,161,171-174,181 switchport trunk allowed vlan add 400 switchport mode trunk switchport nonegotiate channel-protocol lacp channel-group 12 mode active and portchannel 11 and 12 config as below : interface Port-channel11 switchport trunk native vlan 400 switchport trunk allowed vlan 2,3,11,15,18,50,52-54,62,64-66,161,171-174,181 switchport trunk allowed vlan add 400 switchport mode trunk switchport nonegotiate ! interface Port-channel12 switchport trunk native vlan 400 switchport trunk allowed vlan 2,3,11,15,18,50,52-54,62,64-66,161,171-174,181 switchport trunk allowed vlan add 400 switchport mode trunk switchport nonegotiate Switch C2960 - 2 interface GigabitEthernet1/0/33 switchport trunk native vlan 400 switchport trunk allowed vlan 2,3,11,15,18,50,52-54,62,64-66,161,171-174,181 switchport trunk allowed vlan add 400 switchport mode trunk switchport nonegotiate channel-protocol lacp channel-group 11 mode active ! interface GigabitEthernet1/0/34 switchport trunk native vlan 400 switchport trunk allowed vlan 2,3,11,15,18,50,52-54,62,64-66,161,171-174,181 switchport trunk allowed vlan add 400 switchport mode trunk switchport nonegotiate channel-protocol lacp channel-group 11 mode active ! interface GigabitEthernet1/0/35 switchport trunk native vlan 400 switchport trunk allowed vlan 2,3,11,15,18,50,52-54,62,64-66,161,171-174,181 switchport trunk allowed vlan add 400 switchport mode trunk switchport nonegotiate channel-protocol lacp channel-group 12 mode active ! interface GigabitEthernet1/0/36 switchport trunk native vlan 400 switchport trunk allowed vlan 2,3,11,15,18,50,52-54,62,64-66,161,171-174,181 switchport trunk allowed vlan add 400 switchport mode trunk switchport nonegotiate channel-protocol lacp channel-group 12 mode active ! and portchannel 11 and 12 config on switch 2 interface Port-channel11 switchport trunk native vlan 400 switchport trunk allowed vlan 2,3,11,15,18,50,52-54,62,64-66,161,171-174,181 switchport trunk allowed vlan add 400 switchport mode trunk switchport nonegotiate ! interface Port-channel12 switchport trunk native vlan 400 switchport trunk allowed vlan 2,3,11,15,18,50,52-54,62,64-66,161,171-174,181 switchport trunk allowed vlan add 400 switchport mode trunk switchport nonegotiate And the configuration i have done on Fortigate 400E(HA) - 1 & 2 is as below : edit "Cisco_LAN" set vdom "root" set vlanforward enable set type aggregate set member "port9" "port10" "port11" "port12" Now the issue is with the ports. One switch acting as active and the other shows standby/passive(ports 33,34,35,36). If i disconnect switch-1 which is active then other switch starts the traffic after 30 seconds on particular ports 33,34,35,36 only. I want to achieve the network as active-active and which will be useful for me in case if needs more pipe. Please help with the config. Simple network diagram attached. Thanks Rohit K