FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
esalija
Staff
Staff
Article Id 418271
Description This article describes the issue of FortiSwitches using Hardware Switch as an Interface type going offline after updating the FortiGate from v7.6.2 to v7.6.4. The article provides a step-by-step workaround to resolve this issue.
Scope FortiGate, FortiSwitch.
Solution

Execute the command below to verify the FortiSwitch Status via CLI:

 

execute switch-controller get-conn-status

 

  • To resolve the issue of FortiSwitches going offline after updating the FortiGate from v7.6.2 to v7.6.4, follow these steps:
  • Enable the Spanning Tree Protocol (STP) setting on the hardware-switch FortiLink interface.
  • To do this, go to

 

config system interface

    edit <FortiLink_hardware_switch_interface>

        set stp enable

end

 

From GUI:

 

FSW89.png

 

  • After enabling STP, the FortiSwitches should come back online.
  • Then, update the first FortiSwitch to v7.6.4.
  • After updating the first FortiSwitch, the switches may go offline again.
  • To resolve this, disable STP on the FortiLink interface by running the command set stp disable.
  • Once STP is disabled, the FortiSwitches should come back online, and you can update the remaining switches to the highest possible version.

 

Notes:

  • This specifically applies to FortiLink interfaces that are set with the type as 'Hardware-switch' on FortiGate.
  • This guide provides a temporary workaround while a patched version is released.

 

Related articles:
Troubleshooting Tip: Fix FortiSwitch showing with the 'Offline' status

Technical Tip: Upgrading FortiOS with FortiLink-enabled FortiSwitches