Created on
03-16-2022
01:02 AM
Edited on
08-07-2025
04:18 PM
By
Stephen_G
| Description | This article describes config error where two FortiSwitches are connected to 802.3ad aggregate (dedicated to FortiSwitch) interface on FortiGate. |
| Scope | FortiGate, FortiSwitch. |
| Solution |
In some cases, the requirement is to manage two FortiSwitches directly to the FortiGate without any inter switch link (ISL) between the switches.
The correct interface type which that should be configured on the FortiGate is hardware switch or software switch and not an 802.3ad aggregate as explained in Single FortiGate unit managing multiple FortiSwitch units (using a hardware or software switch inter....
For example - if an 802.3ad aggregate interface type is defined on the FortiGate with two ports as members of the aggregate interface, and an administrator connects a different FortiSwitch on each member: only one of the two FortiSwitches will come online.
The reasoning behind this behavior is that 802.3ad (Link Aggregation Control Protocol) is designed to negotiate with only one other peer on a given aggregate.
Without using a technology like Multi-Chassis Link Aggregation (MC-LAG) , the topology resulting from the situation described in the previous paragraph causes two separate LACP peers to be present on the aggregate from the perspective of the FortiGate. The result is that the Link Aggregation Control Protocol will only complete negotiation with one of the two FortiSwitches and the aggregate does not form on the other. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.