Fortigate HA Failover issue with clients connected to vlan with intra-vlan-blocking enabled
The issue:
Clients connected to a vlan with Block intra-VLAN enabled can't reach the FortiGate for around 2 minutes and 30 seconds after failover. Clients connected to a vlan with no Block intra-VLAN enabled do not have this issue.
All switches are managed by the Fortigate.
Topology:
2 X Fortigate 601F in HA A/P
2 X Core switches FortiSwitch 1024E in MCLAG
2 X FSR-216F-POE connected in a ring to the MCLAG switches. So, the first switch connects to the first 1024E switch and the second connects to the second 1024E switch with a link between the two FSR-216F-POE switches. (We can't change this because of the physical fibers)
I have tested with two clients connected to the same switch. Client A connected to port 1 on a vlan with intra-vlan blocking enabled, and Client B connected to port 2 on a vlan with intra-vlan blocking disabled.
Client A was having issues after the failover and could not reach the Fortigate for around 2 minutes and 30 seconds. Client B does not have any problems. It looses one ping after failover and works fine.
I have a support case open now for around 3 months. I still have no solution or information to work with.
Can somebody help me here?
Support confirmed all physical cabling and MCLAG configuration is all completely fine. No spanning-tree issues or anything.
FortiGates are running 7.4.9 and FortiSwitches are running 7.6.4