Description | This article describes the limitations of the fail-detect feature on FortiGate devices, specifically when used recursively. It explains how the feature may work as expected or exhibit unexpected behavior, and provides information on how to address these limitations. |
Scope | FortiGate. |
Solution |
Failure detection for aggregate and redundant interfaces
Example of configuration:
config system interface edit "agg1" set vdom "root" set fail-detect enable set fail-alert-method link-down set fail-alert-interfaces "agg2" set type aggregate set member "port1" "port2" next edit "agg2" set vdom "root" set fail-detect enable set fail-alert-method link-down set fail-alert-interfaces "agg1" set type aggregate set member "port3" "port4" next end
Technical Tip: What is the reaction time of fail-detect
However, if a recursive fail-detect configuration is implemented, the reaction time might be delayed (~10 seconds), and the delay can be observed usually during the first setup/after device reboot.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.