Skip to main content
JonasV
Explorer
November 9, 2021
Solved

L3 VLAN interface up, but IP/Network missing under locally connected network

  • November 9, 2021
  • 11 replies
  • 10879 views
Hi everyone, I’m faceing a strange issue on a FortiGate. I have two 100F running in an A-P HA Cluster. I have an aggregater interface connected to a Cisco Nexus 9K. The LACP between the Cisco switch and the 100F FortiGate is up and running. I’ve created serveral VLANs on the aggregated interface. They are working perfekt. Today I added another VLAN interface to the aggregated link on the FortiGate. I’ve confirmation that the MAC andres of the VLAN interface is pressent and detected on the Cisco Switch. However… The L3 IP that I have configured is up/up on the FortiGate, but I’m unable to ping the interface from the FortiGate itself. After some basic troubleshooting, I came across that the IP/network of the VLAN interface doesn’t show up under the locally connected part of the routing table. I’ve been unable to solve the issue so far. By the way, I’m running FortiOS 6.2.9.
    Best answer by JonasV

    Root cause was found to be in the FortiOS 6.2.9
    After upgrading to 6.2.10, this issue was resolved.

    11 replies

    pkungatti_FTNT
    Staff & Editor
    Staff & Editor
    November 22, 2021

    Dear Jonas

    Your issue required to verify configuration and do deeper troubleshooting. I would suggest to raise a ticket with Fortinet technical support.

     

    Visit us at https://community.fortinet.com to get answers to questions, technical documentation, and collaborate with Fortinet global community.

    GDiFi
    Staff
    Staff
    November 22, 2021

    Can you post the output of the following as well as what IP address is on the interface?  A configuration of the interface could be helpful as well from #Config system interface.

     

    # get router info routing-table database

     

    JonasV
    JonasVAuthor
    Explorer
    November 25, 2021

    I've created a TAC support ticket for the issue.

     

    My findings so far is, that the networks are injected to the locally connected routing table if I create the interfaces directly onbox, either via GUI or CLI.

    However since the FortiGate is managed via our FortiManager i'll usually create and push config from it. And it is when done via the Fortimanager that the issue occure

    JonasV
    JonasVAuthor
    Explorer
    November 25, 2021

    Investigation so far suspects that the downgrade from 6.4.x to 6.2.x, might have resolved in this behavior.

    Next step for me is to format the FortiGates, install FortiOS 6.2.x again and import config.
    Hopefully this fixes the issue

    JonasV
    JonasVAuthorAnswer
    Explorer
    January 5, 2022

    Root cause was found to be in the FortiOS 6.2.9
    After upgrading to 6.2.10, this issue was resolved.

    Toshi_Esumi
    SuperUser
    SuperUser
    January 5, 2022

    I wouldn't jump to the conclusion only because upgrading it to 6.2.10 solved the problem, unless you found it in the release notes. When you upgraded, it was rebooted and LACP needed to re-negotiate and sync again with remote on both FGT and Nexus side.

     

    Toshi

    JonasV
    JonasVAuthor
    Explorer
    January 5, 2022

    Hi @Toshi_Esumi 

    Root cause and the bug was identified as part of Fortinet TAC support ticket, and verified by their engineering staff.
    As per their suggestion, I upgraded to 6.2.10 as they had solved the issue with this build.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!