Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
meliodes
New Contributor

Switch blocking uplink to FG80F after 6.4.9 update

Last night I updated my Fortigate 80F from 6.4.8 to 6.4.9 and immediately lost connection to the LAN. I could still ping the Fortigate from the internet side, so on a hunch I checked the switch (a Unifi 24PoE) and noticed the port the 80F is plugged into was blocked. Disabling STP on the port makes everything work again. I'm not sure if it's a Ubiquiti problem or a Fortigate problem, but it had been running fine on 6.4.8 for months. There's only one connection between the 80F and the switch. RSTP priority on the switches is set to 4096 on the 24PoE and 8192 on a couple of downstream switches. I skimmed the release notes for 6.4.9 and nothing stood out that might cause this kind of issue...any ideas?

omeglexender
13 REPLIES 13
Anonymous
Not applicable

Hello meliodes, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

 Fortinet Community Team 

Anonymous
Not applicable

Hi meliodes,

 

That issue would require in-depth investigation, and that would be best for you to create a support ticket for that to know the root cause. 

 

Hope this helps!

 

Regards

RJ 

Jeffcander
New Contributor

I have come across the same issue.  Did you ever get this resolved?

jweisz
New Contributor

This just took down our entire network. I can't find any mention of spanning tree in the release notes for 6.4.9, and a technical tip in 2020 claims that FortiGates don't participate in STP, but... apparently they do now? You can switch STP off on the FortiGate interface, and you should be back in business.

alif
Staff
Staff

Hello @meliodes,

 

Please check if STP is enabled on the port that is connecting to Unifi switch.

 

config system interface

edit <interface_name>

show full | grep stp

 

If the above output shows STP is enabled, then this could be the reason that you lost access to the LAN.

Regards,
SFA
jweisz
New Contributor

@alifThe issue in this case is not that STP is enabled (obviously, it is for this issue to occur). The issue is that STP was enabled (no config change) in 6.4.8, and did not cause this issue. So something about the 6.4.9 release changed STP functionality, and I don't see anything documented in the release notes. I am unsure if STP was just broken in 6.4.8, and 6.4.9 fixed it, or if some other change adjusted how STP determines if it believes there's a loop.

 

Fortinet needs to identify and document the related change.

alif

I did find an internal Engineering ticket that has a similar issue reported after firmware upgrade from 6.4.8 to 6.4.9. It's still being investigated and currently no fix is available.

Regards,
SFA
MattPolichany

I'm having this issue as well on 7.2.0

syordanov

Hello MattPolichany,

 

Could you please tell me the model of your Fortigate ?

 

.
Labels
Top Kudoed Authors