Multiple VLAN Trunking causing 100% CPU spike on 60E
I'm hoping someone will be able to offer me some advice please, I have an issue configuring VLAN trunking, which when I enable the config I think should work, the CPU runs up to 100% on my Fortigate 60E and the device becomes unresponsive.
Very Basic topology looks like this:
Wired Users --> Zyxel GS1900-48HP --> Fortigate 60E --> Internet
Wireless Users connect first to a Cisco WAP121, which is connected to the Zyxel switch above.
Current setup (Fortigate 60E):
I have created a Hardware Switch called 'Inter-VLAN' in the Network | Interfaces section, and added interfaces 2 to 7 as members.
I then created six VLAN sub-interfaces under the 'Inter-VLAN' switch, with VLAN IDs 20, 30, 40, 50, 60, and 70. Each with it's own subnet, DHCP server, and DNS server.
Current setup (Zyxel GS1900-48HP):
Access ports are configured with the appropriate PVIDs, and are marked as 'un-tagged' on the appropriate VLAN ID.
Port 11 is configured as a Trunk, has a PVID of 1, is un-tagged for VLAN1, and tagged for VLANs 20, 30, 40, 50, 60 and 70.
Port 11 connects to interface 2 on the Fortigate 60E.
The current setup described above works, all end points are receiving their appropriate addresses from their respective DHCP servers, and are connecting through the SD-WAN to the internet correctly, all IPv4 policies are working as they should.
The problem occurs when I try to balance out the load of traffic from the Zyxel to the Fortigate by configuring additional trunk ports. For example, if I configure port 13 on the Zyxel in the exact same way as port 11 (the current trunk), and connect to port 3 on the Fortigate, everything stops working. The fortigate becomes unresponsive almost immediately, no internet access, and I can't access the Zyxel switch either.
I have tried many combinations of PVID assignment, VLAN tagging, and it seems no matter what I try, I keep getting the same result.
Does anyone have any thoughts , questions or suggestions?
Thank you for your patience on this, I am migrating to this solution having previously used a Cisco 897VA (which incidentally had one VLAN assigned per physical port, and the Zyxel connected to it with dedicated trunk ports each tagged for a single VLAN).