Skip to main content
PaulPo
Visitor III
August 7, 2026
Question

Telnet Intermittency Issue via FG-50G Transparent Mode Aggregate Trunk

  • August 7, 2026
  • 3 replies
  • 129 views

When I attempt to Telnet into a Cisco switch located downstream of a FortiGate 50G (FG-50G), the Telnet connection fails.

However, through cross-testing, I discovered an odd workaround: Whenever I modify any Firewall Policy on the FG-50G (even an irrelevant change, such as removing a service from a disabled policy), the previously failed Telnet connection to the downstream switch suddenly starts working normally.

Unfortunately, if the system is left idle for a while, the Telnet connection issue returns.

Network Architecture & Environment Setup

  • Upstream & Downstream Switches: Cisco switches, connected via LACP configured to allow all VLANs.

    Plaintext

     

    interface Port-channel1
    switchport mode trunk
    end
  • FortiGate 50G: Configured in Transparent Mode.

  • Aggregate Interface Configuration:

     

    edit "downlink"
    set vdom "root"
    set allowaccess ping https ssh snmp radius-acct
    set broadcast-forward enable
    set l2forward enable
    set stpforward enable
    set type aggregate
    set member "port9" "port10"
    set device-identification enable
    set lldp-transmission enable
    set role lan
    set snmp-index 33
    next
    end
  • Sub-interface Configuration (Only VLAN 4 used for Management):

     

    edit "downlink-v4"
    set vdom "root"
    set allowaccess ping https ssh snmp radius-acct
    set broadcast-forward enable
    set l2forward enable
    set stpforward enable
    set forward-domain 4
    set device-identification enable
    set role lan
    set snmp-index 35
    set interface "downlink"
    set vlanid 4
    next
    end

3 replies

Stephen_G
Staff & Editor
Staff & Editor
August 11, 2026

Hi PaulPo,

Thank you for using our forums. We’ll look to get you an answer or help.

In the meantime, if anybody else has any suggestions, please feel free to contribute.

Stephen_G - Fortinet Community Team
Stephen_G
Staff & Editor
Staff & Editor
August 13, 2026

Hi PaulPo,

We are still looking to get you an answer or help. We will reply to this thread once we find some.

Stephen_G - Fortinet Community Team
New Member
August 13, 2026

On my RT-BE90U (firmware 3.0.0.6.102_58390-g892db0c_1170-g9c6c7_Q7MB, PPPoE 500/75 Mbps), adding even one URL or Keyword Filtering rule drops upload speed from ~75 Mbps to ~0.5 Mbps. Download stays normal. Removing the rule instantly fixes it.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!