Hello Engineers.
I have this Fortinet configuration with HA active-passive mode, and an aggregate was configured with port3 and port4 on the fortinet side and in each Huawei Switch that is in Stack mode and 802.3ad LACP with two ports was created
The LACP on the Switch side always shows up, but on the fortinet side, it always shows us down the lacp in the Active and Passive Firewall when I run a diag net aggr name Lacp_SW the status is down,in the both of them.
I would like to ask you for help if this behavior is normal, where the Active and passive always looks down.
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello @Ahmedaz ,
This is not normal. You can troubleshoot lacp issue with that document. Sometimes, you need some custom configuration on switch side like lacp mode.
Hello @ozkanaltas
Thanks for Reply , Now the Active one Appear that Aggregate is UP but still in the Passive one is DOWN
Hello @Ahmedaz ,
This is normal behavior. Passive units share the same Mac address as the master unit and always stay in standby mode and can't respond to lacp packets.
If you want to learn if it's working or not, you can failover your firewall. After the failover process lacp should work on 2nd unit.
And also you can review LACP topologies in this link.
Thanks for reply @ozkanaltas
the issue is i tried to test it when the Active on is changed to be secondary and the secondary become the Active on it not working the Aggregation interface is DOWN
Any help ??
Did you apply troubleshooting steps for the second unit?
At first, you said that LACP was not working on the main unit either, what did you do to make it work? Can you make this change in the second unit?
yes , in the main part in the first isn`t working , because there is a missing command in switch to enable LACP mode , after add the command the main part is working now.
but still the passive part is down even when i check via the command ((diagnose netlink aggregate name OOB-SW))
Can you send the output of this command?
diagnose netlink aggregate name OOB-SW
Created on 05-26-2024 09:29 AM Edited on 05-26-2024 09:46 AM
sure
This is normal because the passive unit can't respond to the lacp package.
When you fail over between devices, that is, when you activate the passive device, does lacp work or not?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.