Skip to main content
Rehad
New Member
February 6, 2024
Question

Fortigate 1100 LACP Problem

  • February 6, 2024
  • 10 replies
  • 5782 views

Hello,

 

We have a Fortigate 1100 connected to a Cisco NX-3548 with 2 LACP links for WAN internet access . In some heavy network traffic days ( three times  in six months )  Both of two LACP links to Cisco NX gets blocked. I am thinking that LACP flapping occurs. 

 

These are 10G fiber connections. Are stock transceivers can be a cause of this problem ?

 

Thanks

10 replies

AEK
SuperUser
SuperUser
February 6, 2024

Hello Rehad

Which FortiOS version?

Did you perform any action to unblock the links or it came back by it own once traffic was low again?

Do you have any relevant system logs from FG and Cisco sides at the moment of the outage?

 

AEK
Rehad
RehadAuthor
New Member
February 6, 2024

Fortigate firmware version is v7.2.6.

 

Unfortunately we couldn't get any logs from FG and Cisco because specialized persons were not present at that time. Only thing we can do is restarting the FG. After restart everything was fine.

 

AEK
SuperUser
SuperUser
February 6, 2024

Your issue looks quite similar to that one affecting FOS 7.2.6 on FG 1100E.

Probably you will have to wait for next patch and open a ticket in case there is a workaround. Meanwhile if the impact is high then you might need to drop the LACP.

861962

When configuring an 802.3ad aggregate interface with a 1 Gbps speed, the port's LED is off and traffic cannot pass through. Affected platforms: 110xE, 220xE, 330xE, 340xE, and 360xE.

AEK
Rehad
RehadAuthor
New Member
February 6, 2024

Once the problem occurs there was stock transceivers . Current information of this transceiver is as follows;

 

Interface port25 - SFP/SFP+/SFP28, 10GBASE-SR
Diagnostics : Implemented
Vendor Name : OEM
Part No. : SFP-10G-SR-LL
Serial No. : 202009281816
Measurement Unit Value High Alarm High Warning Low Warning Low Alarm
------------ ------------ ------------ ------------ ------------ ------------ ------------
Temperature (Celsius) 31.6 90.0 85.0 -5.0 -10.0
Voltage (Volts) 3.37 3.60 3.50 3.00 2.90
Tx Bias (mA) 6.89 15.00 13.00 2.00 1.00
Rx Power (dBm) -40.0 -- 5.0 3.0 -15.0 -17.0
Tx Power (dBm) -2.6 4.0 3.0 -8.0 -9.0
++ : high alarm, + : high warning, - : low warning, -- : low alarm, ? : suspect.

 

Some figures are not within the limits. Both of the transceivers were stock transceivers. This can be the cause of the problem ?

AEK
SuperUser
SuperUser
February 6, 2024

I don't know if this OEM SFP can cause such issue or not, but in my experience they generally work fine. However it is possible that you will not get support from Fortinet on issues related to this SFP, but you can always try.

AEK
Rehad
RehadAuthor
New Member
February 6, 2024

Thanks AEK,

 

We may think to drop LACP because the impact is quite high. But that time there are too many Firewall policy rules using wan1 ( LAG interface name ) . Is there a way keeping this wan1 interface and rules by dropping the LACP.

 

Thanks Again

Rehad
RehadAuthor
New Member
February 6, 2024

Actually i forgot the mention the SD-WAN definition.

 

LAG interface name wan1 is used in the SD-WAN definition , which has wan1 and wan2 . wan2 is not used , there is no physical connection for wan2.

 

the SD-WAN name ( WAN ) is used in all of the Firewall policy rules.

AEK
SuperUser
SuperUser
February 6, 2024

You may try with Interface Migration utility

  • Go to Network > Interface
  • Select the interface
  • Click on "Integrate Interface" button
  • Follow the wizard until the end

You should try firs in lab to master the procedure and check it works fine before going on prod.

Don't forget to take a full backup before the operation.

Do it during maintenance window (possible downtime).

AEK
Rehad
RehadAuthor
New Member
February 6, 2024

Thanks a lot, i will try this.

Rehad
RehadAuthor
New Member
February 6, 2024

I have read the Fortigate document about interface integration wizard unfortunately the below explanation says that we can't do this operation;

 


"The interface migration wizard does not support turning an aggregate, software switch, redundant, zone, or SD-WAN zone interface back into a physical interface."
Rehad
RehadAuthor
New Member
February 6, 2024

What i am thinking , i will use another port for  wan internet access . I will create one by one each firewall rule for this new port ( it will take some time but its doable ) . I will disable old connections ( SD-WAN , LACP etc ) and i will move to this new port .

AEK
SuperUser
SuperUser
February 6, 2024

Yes you can do so.

To speed up the change you can use cli script so you can do it much faster.

Just make a good plan and test it in your lab.

AEK
Rehad
RehadAuthor
New Member
February 6, 2024

Ok thanks , i will use cli scripts.

jpcastilloux
New Member
April 18, 2024

Have you resolved your problem ?

 

We are experiencing something that's look the same.

 

We have LACP communication problem with a 600E.

LACP doesnt goes down, always up, but we have traffic unstability.

If we ping the gateway using this LACP ( while being in the same VLAN ), we are losing a lot of ping...like a arp poising problem or arp conflict...but there is not, everything has been verified.

 

BUT ! If we hard reboot the cluster ( by unpluging the power cable, not only the reboot button in the GUI ), the problem is resolved UNTIL a LACP member is down for a moment ( by manually shutting down the port by CLI or physicaly unpluging it from the switch ).
When this happens, all the problems comes back until we hard reboot again the cluster....

 

Very strange behavior...

Rehad
RehadAuthor
New Member
April 19, 2024

Hi jpcastilloux,

 

We understood that the root of the problem was some DDOS attacks. The instability happens under heavy internet traffic. We have two ISPs for Internet connection . One is primary and the other secondary . To minimize the incoming internet traffic we have switched the ISP and selected the slower one for the first priority. Slower ISP speed is 1 Gbit/sec . 

 

After this we don't faced any problem on the LACP link.

 

We were planned to remove the LACP but as we didn't have a problem anymore we didn't do that. 

 

 

Rehad
RehadAuthor
New Member
April 19, 2024

Also i have to mention that the ISP that we have selected as the first priority has better infrastructure for preventing DDOS attacks.