FortiGate HA-to-HA Design: Hardware Switch vs LACP Aggregate Interface
Hello everyone,
I would like to get some feedback from the community regarding a design decision between using a Hardware Switch interface or an LACP Aggregate interface in a FortiGate HA deployment.
Scenario
I have two Active-Passive FortiGate HA clusters interconnected directly, similar to the topology below:

The objective is to maintain connectivity during a failover event on either cluster while keeping the design as simple and stable as possible.
Current Design
We are currently using a Hardware Switch interface across the participating ports. The solution has been operating correctly and failover testing has been successful.
Question
From a Fortinet best-practice perspective:
-
Would you prefer Hardware Switch or LACP for this topology?
-
If LACP is preferred, would you configure
lacp-ha-secondary disableon both clusters? -
Have you experienced any MAC flapping, convergence, or failover issues when using LACP directly between HA clusters?
One of the reasons I am evaluating both options is that Fortinet documentation mentions that when lacp-ha-secondary disable is configured, the secondary unit does not participate in LACP negotiations. As a result, during a failover event the new primary must establish LACP negotiation before it can start forwarding traffic, potentially increasing convergence time.
For those who have implemented similar designs in production, have you observed any noticeable impact during failover events when using LACP compared to Hardware Switch interfaces?
I would appreciate hearing real-world experiences and design recommendations.
Thank you.
