FortiGate 901G HA Cluster with Cisco Switch Stack Using LACP – Best Practice Configuration
I am looking for a best-practice and supported configuration for setting up two FortiGate 901G devices in an HA cluster and connecting them to a Cisco switch stack/cluster using LACP.
Environment Details:
FortiGate model: 901G (2 units)
HA mode: Not decided yet (Active-Passive or Active-Active)
Switching environment: Cisco switch stack / clustered switches
Link aggregation: LACP (802.3ad)
Objective:
High availability at the firewall level
Redundant and aggregated uplinks to the Cisco switch stack
Stable and supported HA + LACP design
Avoid split-brain, MAC flapping, or failover issues
Questions:
What is the recommended Fortinet-supported topology for FortiGate 901G HA when using LACP to Cisco switch stacks?
Should LACP be configured using a FortiGate aggregate interface, and should it be created before or after HA is enabled?
Is Active-Passive HA preferred over Active-Active when using LACP with Cisco switch stacks?
How should the Cisco side be configured (single port-channel across stack members, trunk mode, LACP active)?
Are there any specific FortiOS settings or limitations for HA + LACP that I should be aware of?
Are there any official Fortinet documentation or reference designs for this setup?
I would appreciate guidance from Fortinet engineers or experienced community members, including recommended topology, CLI examples, or documentation references.
Thank you in advance for your support.
