Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Zekeout
New Contributor II

FortiSwitch - MCLAG Firmware Update/Mismatch

Good Morning,

 

Has anyone ran into issues when updating the firmware on MCLAG switches that would cause the switches to disconnect? I'm wondering if the MCLAG group of switches need to be updated to the same firmware at the same time?

 

Topology:

FW1 & FW2 (HA Active/Passive)

SW1 & SW2 MCLAG Group 1 (SW1 connected to SW3)(SW2 connected to SW4)

SW3 & SW4 MCLAG Group 2 (SW3 connected to SW5)(SW4 connected to SW6)

SW5 & SW6 MCLAG Group 3

 

SW1 & SW2 are running FortiSwitchOS 7.4.1

SW5 & SW6 have been updated to FortiSwitchOS 7.4.3

 

After updating SW4 to FortiSwitchOS 7.4.3 last night we lost access to switches 3-6. 

The log message that stands out is "action="unsup-cfg" status="none" msg="MCLAG: **peer software mismatch local-software(v7.4.1,build0787,230921 (GA)) peer-software(v7.4.3,build0830,240422 (GA))""

 

Disabling the port on SW1 that connects to SW4 gave us access back to SW3-5 but SW6 is still down.

 

I'm assuming that updating SW3 to 7.4.3 will fix the problem but wondering if anyone else has seen similar issues?

We did update SW5 and SW6 separately from 7.4.1 to 7.4.3 (SW6 first and then SW5) without any issues which seems odd.

 

Thanks! 

1 Solution
tgauvey_FTNT
Staff
Staff

Hello,

 

Yes, FortiSwitches in MC-LAG need to be on the exact same firmware. Fortinet recommends that you update them at the same time. You can do this by going to Switch and WiFi Controller > Managed FortiSwitches and shift clicking your two switches. Then click upgrade on them.

Tommy Gauvey

View solution in original post

2 REPLIES 2
tgauvey_FTNT
Staff
Staff

Hello,

 

Yes, FortiSwitches in MC-LAG need to be on the exact same firmware. Fortinet recommends that you update them at the same time. You can do this by going to Switch and WiFi Controller > Managed FortiSwitches and shift clicking your two switches. Then click upgrade on them.

Tommy Gauvey
Zekeout

Updating the firmware on the 2nd MCLAG group switch seems to have corrected the problem - thank you!

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors