Question
Fortigate VLAN interfaces
I am trying to configure to Internet connections into my Fortigate device. I have two Fortigate in HA (60B in my lab). I have configured VLAN interfaces off WAN2 (ISP1-VLAN16, ISP2-VLAN19). I am trying to test out the whole process of aging out the MAC-ADDRESS on my switch that the Fortigates are patched into age out should the ISP link go down. I have dead gateway detection configured in the firewall and the route disappears when I disconnect one of the ISP links and the traffic fails over after a period of time. I was also hoping to see the MAC-ADDRESS disappear out of my switch for completeness and come back when the interface (ISP link) was re-establised. The MAC address never goes though as the Admin Status of the VLAN interface on the Fortigate remains up. Is there any way you can get the VLAN interface to go ' Admin down' other than doing this manually? I now its not a big issue as the traffic gets routed via the other ISP link. Also, when a link fails and the traffic is re-routed, when the link comes back online why does the traffic revert back to the old link (previously failed link) and not stay on the link it failed over to? Thanks Darren
