Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Carl_Wallmark
Valued Contributor

Experience with Fortigate HA and HP Procurve switches?

Hi, I have 2 FG 200A set up in a HA and with alot of VLANS, Does anyone have any experience with HP Procurve (2600) switches and trunking between FG and Switches, i´m having a bit problem with how to configure trunking on the switch, its working when i have Trunk1 to one of my FG and Trunk2 to the other but not when Trunk1 is connected to both. Is there anyone who have a working setup like this ??

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
14 REPLIES 14
UkWizard
New Contributor

ensure you are using 802.1q trunking method and that the trunked port to the fortinet is configured (tagged) for all the trunks you want to see at the fortinet end. Should work, have not personally done it with procurves though, but doubt its undoable.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Carl_Wallmark
Valued Contributor

my setup is like this: FG1 -----Trunk1-----> HP Switch | -- HA Cluster FG2 -----Trunk2-----> Same HP Switch This way it works, but if a do like this: FG1 -----Trunk1-----> HP Switch | -- HA Cluster FG2 -----Trunk1-----> Same HP Switch Then it fails. Should i use Spanning Tree ?? (STP, RSTP, MSTP) Thanks!

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
doshbass
New Contributor III

Actually, from the description, I would have expected scenario 1 not to work and scenario 2 to work. In an HA environment, you should not have to setup spanning tree Can you be more precise about what exactly fails? Fortinet and ProCurve are strategically alligned, therefore you should be able to get help from either procurve or Fortinet support for the entire issue. Having sid that the alliance is only about 6 months old, so they may be catching up with each other' s products.
Still learning to type " the"
Still learning to type " the"
UkWizard
New Contributor

I agree with doshbass, i would of expected the latter to work. However, what mode is the cluster in? as this would probably affect the setup.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Carl_Wallmark
Valued Contributor

i will loose contact with my cluster if a use scenario 2, i seems like the procurve switch gets confused. If i turn off one of the FG´s it starts to work again. So my solution was to make 2 different trunk ports instead of 1. But i dont think the load balance will work because the switch is only using one of the trunk ports, and holding the other port in " stand by" mode. so thats why i wondered if someone had som experience with HP Procurve switches =)

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Carl_Wallmark
Valued Contributor

right now i´m using Active-Passive, only because load balancing is not working as i expected, but i would like to run in Active-Active mode.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
UkWizard
New Contributor

Sounds like you have spanning tree on, turn it off. If i remember correctly the two units would share the same IP and virtual MAC, thus STP would break this.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Carl_Wallmark
Valued Contributor

how will the procurve switch handle the same MAC on two different ports ?? Will it not get confused ??

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
doshbass
New Contributor III

The MAC jumps from old master to new master so will not appear on two switches. However if you turn on spanning tree on teh switches one switch will effectivly block teh Master from seeing its slave
Still learning to type " the"
Still learning to type " the"
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors