Description |
This article describes how to handle connections that are down/flapping between FortiGate and MCLAG FortiSwitches after upgrading the switches. |
Scope | FortiGate, FortiSwitches. |
Solution |
When FortiGate and FortiSwitches are connected and set up with MCLAG switches, after upgrading FortiSwitches, the connection status in the FortiGate GUI shows as down or flapping.
The following logs need to be collected in the FortiGate:
diagnose switch mclag-peer-consistency check <mclag_trunk_name>
Output will show the details of config syn between the switches and port status:
diagnose switch mclag peer-consistency-check 8FFTF2304118 ** Comparing "switch.trunk" config ....OK Comparing "LAG state"
Comparing "STP state" STP instance misconfiguration missing in instance-33 in local config <--
### diagnose switch mclag icl Counters received keepalive packets 185547
Solution: FortiSwitches in MC-LAG need to be on the exact same firmware. Fortinet recommends upgrading the switches at the same time. This can be done by following Switch and WiFi Controller -> Managed FortiSwitches, then pressing shift, and selecting two switches. After, select Upgrade on them. |