Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ahmedaz
New Contributor

Aggregate Down in Active and Passive Firewall

Hello Engineers.

I have this Fortinet configuration with HA active-passive mode, and an aggregate was configured with port3 and port4 on the fortinet side and in each Huawei Switch that is in Stack mode and 802.3ad LACP with two ports was created 

 

The LACP on the Switch side always shows up, but on the fortinet side, it always shows us down the lacp in the Active and Passive Firewall when I run a diag net aggr name Lacp_SW the status is down,in the both of them.

 

I would like to ask you for help if this behavior is normal, where the  Active and passive always looks down.

 

Thanks 

10 REPLIES 10
ozkanaltas
Valued Contributor III

Hello @Ahmedaz ,

 

This is not normal. You can troubleshoot lacp issue with that document. Sometimes, you need some custom configuration on switch side like lacp mode. 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Initial-troubleshooting-steps-for-LACP-Lin...

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Ahmedaz

Hello @ozkanaltas 

Thanks for Reply , Now the Active one Appear that Aggregate is UP but still in the Passive one is DOWN

ozkanaltas
Valued Contributor III

Hello @Ahmedaz ,

 

This is normal behavior. Passive units share the same Mac address as the master unit and always stay in standby mode and can't respond to lacp packets. 

 

If you want to learn if it's working or not, you can failover your firewall. After the failover process lacp should work on 2nd unit.

 

And also you can review LACP topologies in this link.

 

https://community.fortinet.com/t5/Support-Forum/Aggregate-Down-in-Passive-Firewall/m-p/206991#M19090...

 

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Ahmedaz

Thanks for reply @ozkanaltas 

the issue is i tried to test it when the Active on is changed to be secondary and the secondary become the Active on it not working the Aggregation interface is DOWN

Any help ??

 

ozkanaltas
Valued Contributor III

Did you apply troubleshooting steps for the second unit?

 

At first, you said that LACP was not working on the main unit either, what did you do to make it work? Can you make this change in the second unit?

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Initial-troubleshooting-steps-for-LACP-Lin...

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Ahmedaz

yes , in the main part in the first isn`t working , because there is a missing command in switch to enable LACP mode , after add the command the main part is working now.

but still the passive part is down even when i check via the command  ((diagnose netlink aggregate name OOB-SW))

ozkanaltas
Valued Contributor III

Can you send the output of this command?

 

diagnose netlink aggregate name OOB-SW

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Ahmedaz

sure

ozkanaltas
Valued Contributor III

This is normal because the passive unit can't respond to the lacp package. 

 

When you fail over between devices, that is, when you activate the passive device, does lacp work or not?

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors