Skip to main content
ahmed_elmelegy
New Member
March 9, 2025
Question

issue with managed fortiswitches

  • March 9, 2025
  • 8 replies
  • 1862 views

hello all, i have 6 floors in a company , each floor has 2 or 3 edge switches and each office in the floor has a small tp-link switch (5port) that compine the PCs, and this small switch connected to the edge and all floors connected to two core switches working as MCLAG and all the switches are managed by fortigate.

i have 3 connection connected direct to the fortigate (ADSL , MPLS , Leased Line).

on the fortigate i have configured a vlan for each floor , when i enable these vlans and assign them to each floor i found a big packet loss in the network but when i work with one vlan for all floors all thing work fine with no isuue.

can anyone help with this issue?

8 replies

AEK
SuperUser
SuperUser
March 10, 2025

Hi Ahmed

Is the packet loss inter-VLAN? Is there packet loss intra-VLAN as well?

AEK
ahmed_elmelegy
New Member
March 10, 2025

Hello AEK

No there is no any packet loss inter vlan

The packet loss when ping from pc to 8.8.8.8 

Another thing i want to know

My design is each edge connected to one peer of the MCLAG not the two.

Can this be the issue or not?

AEK
SuperUser
SuperUser
March 10, 2025

Hi Ahmed

Can you share the following?

  • A screenshot of your FortiLink config from menu Network > Interface
  • A diagram showing how switches are interconnected and how connected with FGT
  • FortiOS version and FortiSwitch OS versions
AEK
ahmed_elmelegy
New Member
March 10, 2025

hi AEK,

thanks for your replying its highly appreciated.

sorry i cannot take a screenshot now as the customer isnt available but i put two port on fortigate under fortilink and disable split. and all vlans under it.

regarding to the diagram this is the diagram

WhatsApp Image 2025-03-10 at 5.07.20 PM.jpeg

fortiOS is 7.4.7

FortiswitchOS is 7.4.5

 

AEK
SuperUser
SuperUser
March 10, 2025

So far seems correct.

Split should be disabled as you did.

If you access switches are 1xx series then you cant connect the last one to the second ToR/Core. So what you did should be correct.

Waiting for the screenshot. But meanwhile, did you use VLAN id 1 for any of the created VLANs?

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.