Skip to main content
darrencarr
New Member
October 16, 2009
Question

Fortigate VLAN interfaces

  • October 16, 2009
  • 7 replies
  • 4417 views
I am trying to configure to Internet connections into my Fortigate device. I have two Fortigate in HA (60B in my lab). I have configured VLAN interfaces off WAN2 (ISP1-VLAN16, ISP2-VLAN19). I am trying to test out the whole process of aging out the MAC-ADDRESS on my switch that the Fortigates are patched into age out should the ISP link go down. I have dead gateway detection configured in the firewall and the route disappears when I disconnect one of the ISP links and the traffic fails over after a period of time. I was also hoping to see the MAC-ADDRESS disappear out of my switch for completeness and come back when the interface (ISP link) was re-establised. The MAC address never goes though as the Admin Status of the VLAN interface on the Fortigate remains up. Is there any way you can get the VLAN interface to go ' Admin down' other than doing this manually? I now its not a big issue as the traffic gets routed via the other ISP link. Also, when a link fails and the traffic is re-routed, when the link comes back online why does the traffic revert back to the old link (previously failed link) and not stay on the link it failed over to? Thanks Darren

    7 replies

    emnoc
    New Member
    October 17, 2009
    Things to think about; The aging timer is set and configured on the L2 siwtch. Cisco defaults to 300secs and if the layer2 port goes down, those address should be expired on that specific switch. The admin status of the vlan interface on the FGT will always be up if the pyshical link is up. Are you pulling the actual FGT layer1 link or doing something else to mimic your failure?
    darrencarr
    New Member
    October 18, 2009
    Hi The timer on my switch is set for 5 minutes. If I remove the patch from my ISP into my switch (disconnect cable) the MAC-ADDRESS eventually ages out. The Fortigate VLAN interface however stays up? I guess I don' t need to worry about this as the actual outgoing interface (MAC-ADDRESS that has been aged out to get out to the NET) as actually been removed and the route also removed from the routing monitor.
    darrencarr
    New Member
    October 18, 2009
    One other question I have regarding this failure.... When I simulate the failure (i.e. remove the patch lead from the switch) the following happens: - dead peer detected - route is removed from routing monitor - http PING intialized before cable removed eventually times out - traffic being routed over the link is routed over the other ISP after approximately 32 seconds Which is all good... however when I re-establish the connectivity (i.e. patch the lead back into the switch) the traffic is re-routed over the restored link, despite it just coming back online and both links being of an equal cost? Seems a bit dangerous to me if a link was going up and down due to a configuration or hardware problem? Can anyone explain why it does this? Thanks
    darrencarr
    New Member
    October 19, 2009
    Also.. You can kind of see what I am trying to do here with the network diagram http://support.fortinet.com/forum/m.asp?m=54841&p=1&tmode=1&smode=1
    emnoc
    New Member
    October 19, 2009
    If I remove the patch from my ISP into my switch (disconnect cable) the MAC-ADDRESS eventually ages out. The Fortigate VLAN interface however stays up?
    That' s normal and expected. The DEAD-GW DETECT does drop the interface vlan. If your worried about equal-cost routes, than set the backup as a higher cost to begin with.
    darrencarr
    New Member
    October 19, 2009
    Hi Thanks for the information. I had tested and documented this in my lab. I am happy with the equal cost routes, thats what I am trying to achieve. Do you know why though if I drop one of the links, the traffic then goes over the other link, but then when the link is re-established is goes back over the link that went down? I can' t find any documentation relating to this?
    brianmac64
    New Member
    November 5, 2009
    Interface priorities? I believe they can be set via the cli
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!