I am looking for a best-practice and supported configuration for setting up two FortiGate 901G devices in an HA cluster and connecting them to a Cisco switch stack/cluster using LACP.
FortiGate model: 901G (2 units)
HA mode: Not decided yet (Active-Passive or Active-Active)
Switching environment: Cisco switch stack / clustered switches
Link aggregation: LACP (802.3ad)
High availability at the firewall level
Redundant and aggregated uplinks to the Cisco switch stack
Stable and supported HA + LACP design
Avoid split-brain, MAC flapping, or failover issues
What is the recommended Fortinet-supported topology for FortiGate 901G HA when using LACP to Cisco switch stacks?
Should LACP be configured using a FortiGate aggregate interface, and should it be created before or after HA is enabled?
Is Active-Passive HA preferred over Active-Active when using LACP with Cisco switch stacks?
How should the Cisco side be configured (single port-channel across stack members, trunk mode, LACP active)?
Are there any specific FortiOS settings or limitations for HA + LACP that I should be aware of?
Are there any official Fortinet documentation or reference designs for this setup?
I would appreciate guidance from Fortinet engineers or experienced community members, including recommended topology, CLI examples, or documentation references.
Thank you in advance for your support.
Solved! Go to Solution.
The topology is as in the KB @AEK pointed you to, but only difference is in your case those cisco switches are stacked, which make them as a single switch. Therefore, all four ports in the KB example, need to have a different number each. Of course, you want to split two legs of a LAG/Port-channel to each physical switch.
The bottom line is, unlike cisco, FGT doesn't support LAG without LACP. You have to configure LACP on both sides.
L1/L2 come up even when the unit is a secondary/passive in a-p, and act as a single link. You would hook up and single link any time regardless both are separated or in HA, wouldn't you?
And, again, LACP is just a link, it wouldn't affect any HA operation, regardless it's a-p or a-a.
Toshi
| User | Count |
|---|---|
| 2842 | |
| 1436 | |
| 812 | |
| 803 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.