Created on
09-25-2025
05:37 AM
Edited on
09-25-2025
05:39 AM
By
Jean-Philippe_P
Description | This article describes the issue when the WAN1 ISP port shows as up but is not passing traffic on SD-WAN with HA A-A. |
Scope | FortiGate. |
Solution |
Issue: Wan1 is showing as inactive, but the interface status appears up.
FW01 # diagnose hardware deviceinfo nic
Troubleshooting steps:
get router info routing-table details 0.0.0.0
execute ping-options source 14.98.4.78
diagnose debug enable Sniffer:
diagnose sniffer packet <interface> <'filter'> 6 0 a
Example: 00:09:0f:09:00:00. This is a virtual MAC address, where the last 4 octets are 00:00 since the group ID is set to 0 (default behavior). Because of this, ARP replies were not being received.
Also, run the below command and check the update below for what is using the Group ID: 0.
get system ha status
To resolve this, configure a group ID. The last 4 octets of the virtual MAC address are derived from the group ID.
Below update after configuration change of group ID to 128.
FGT201F-2 # get system ha status
Once a group ID was configured/added, the last 4 octets of the virtual MAC address were derived from the group ID. After that, ping to the gateway should resolve. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.