Created on
06-17-2022
07:07 AM
Edited on
01-27-2026
01:27 AM
By
Jean-Philippe_P
| Description |
This article will serve as a guide on how to configure the LACP interface on HA-monitored interfaces when LACP is used for multicast traffic. |
| Scope | FortiGate. |
| Solution |
Below shows the interfaces that are part of the LACP configuration.
FGTA-MCAST # diag netlink aggregate name LACPMcastServer status: up npu: n flush: n asic helper: y ports: 2 link-up-delay: 50ms min-links: 1 ha: master distribution algorithm: L4 LACP mode: static
slave: port3 index: 0 link status: up link failure count: 0 permanent MAC addr: 00:0c:29:09:75:6f
slave: port4 index: 1 link status: up link failure count: 0 permanent MAC addr: 00:0c:29:09:75:79
FGTA-MCAST (ha) # show config system ha set group-name "FGT_Multicast" set mode a-p set password ENC set hbdev "port5" 0 set ha-mgmt-status enable config ha-mgmt-interfaces edit 1 set interface "port1" set gateway 100.100.100.2 next end set override enable set priority 200 set monitor "port2" "port3" "port4" end
get system ha status HA Health Status: OK Model: FortiGate-VM64 Mode: HA A-P Group: 0 Debug: 0 Cluster Uptime: 0 days 0:30:17 Cluster state change time: 2022-06-17 21:32:28 Primary selected using:<2022/06/17 21:32:28> FGVM04TM22004042 is selected as the primary because it has the largest value of override priority.
Note: If the LACP interface itself is used on the HA-monitored interfaces, HA monitoring will be delayed when detecting the LACP interface, and this can cause delays in establishing LACP traffic during a FortiGate HA failover.
Note 2: In this example, HA is monitoring the physical member ports (port2/port3/port4) instead of the LACP aggregate. This provides faster detection of link issues, but with 'min-links=1', it also means that the loss of a single member can already trigger an HA failover even though the aggregate is still operational.
Note 3: The aggregate interface on both units will only be shown as up if the downstream switch supports Multiple Link Aggregation (MCLAG) grouping. If the downstream switch does not support MCLAG configuration or HA has been configured with 'set lacp-ha-secondary disable', only the LACP interface on the Primary unit will be shown as up.
The example output is as follows:
FGT02 # get system ha status
Related documents: Aggregation and redundancy |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.