Skip to main content
albertocobo
New Member
January 20, 2023
Solved

HA standby unit ports down

  • January 20, 2023
  • 4 replies
  • 10369 views

Hi,

i'm installing two Fortgate F61 in HA and monitoring two interfaces. They are working as expected and the monitored interfaces in standby unit are up on the switches they are connectaed to.

 

The thing is that i'm interested in having these two interfaces of the Standby unit in down. I know that failover will be a little slow but this is not a problem on this environment.

 

I have been reading CLI reference guide and there is no command to do it (https://docs.fortinet.com/document/fortigate/7.2.3/cli-reference/21620/config-system-ha).

 

Does anyone knows if is it possible?

 

Thanks.

Best answer by albertocobo

Hi bpozdena_FTNT.

 

the "set link-failed-signal enable" moves the port down for one second. 

 

The thing is that connected to FGs I hace two MCLAG switches connected with an aggregate of 2 ports each switch to FGs. I mean, port1 of switches to FG active and port2 of switches to FG standby, all four ports in the same MCLAG aggregate. In the FG side,  one aggregate with ports A and B monitored for failover.

 

FG Active portA --> Sw1 port1 (MCLAG)

FG Active  portB  --> Sw2 port1 (MCLAG)

FG Standby portA --> Sw1 port2 (MCLAG)

FG Standby portB --> Sw2 port2 (MCLAG)

 

If Sw1 port1 fails, the FGs move the active unit making the standby as primary, but SW2 port1 continues sending traffic, and loosing it.

Finally I could solve the situation changing configuration in FG aggregate interface:

 

config system interface
edit "Link-to-SW"
set lacp-ha-slave disable  -->  With this command the stanby unit has the ports level 1 link up but switches ports connected to standby unit are in suspended mode even in failover I explained before.

 

Thanks.

 

4 replies

abarushka
Staff
Staff
January 20, 2023

Hello,

 

As far as I understand you would like stand alone unit just to synchronize configuration/sessions. Can you please confirm?

albertocobo
New Member
January 23, 2023

Yes, sync the config and ethernets in down (except HA of course).

 

Thanks.

bpozdena_FTNT
Staff
Staff
January 23, 2023

Hi @albertocobo ,

 

I do not see any reason/benefit to keeping interfaces shutdown permanently.  You can however enable a temporary interface shutdown after a Fortigate failover occurs in order to force-clear MAC address tables on adjacent switches .

 

config system ha     set link-failed-signal enable end

 

More details at  https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-HA-link-failed-signal-and-switch-MAC/ta-p/198050 .

albertocobo
albertocoboAuthorAnswer
New Member
January 23, 2023

Hi bpozdena_FTNT.

 

the "set link-failed-signal enable" moves the port down for one second. 

 

The thing is that connected to FGs I hace two MCLAG switches connected with an aggregate of 2 ports each switch to FGs. I mean, port1 of switches to FG active and port2 of switches to FG standby, all four ports in the same MCLAG aggregate. In the FG side,  one aggregate with ports A and B monitored for failover.

 

FG Active portA --> Sw1 port1 (MCLAG)

FG Active  portB  --> Sw2 port1 (MCLAG)

FG Standby portA --> Sw1 port2 (MCLAG)

FG Standby portB --> Sw2 port2 (MCLAG)

 

If Sw1 port1 fails, the FGs move the active unit making the standby as primary, but SW2 port1 continues sending traffic, and loosing it.

Finally I could solve the situation changing configuration in FG aggregate interface:

 

config system interface
edit "Link-to-SW"
set lacp-ha-slave disable  -->  With this command the stanby unit has the ports level 1 link up but switches ports connected to standby unit are in suspended mode even in failover I explained before.

 

Thanks.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!