First of all, I am inheriting this network and I believe this to be setup incorrectly however I've never seen someone try to do it this way. I have a two site-to-site fortigates with a switch behind each. I am getting inconsistent pings to the far switch. The far fortigate is also getting intermittent pings to its switch (they are connected via copper which has been swapped out). The LAN interface is set to 192.168.0.1 and the switch's Management interface is set to 192.168.0.2. Under the FG's LAN interface are SVIs for the various vlans on the switch. It seems to me that the problem is likely that the OOB mgmt interface is being used or is there something on the FG side that I should look at?
Solved! Go to Solution.
It sounds like you’re dealing with a complex and possibly misconfigured network setup. Based on the description, here are some points to consider and investigate to pinpoint the issue and improve the setup:
It sounds like the management interface of the switch (192.168.0.2) might be causing routing or traffic issues if it's using the same subnet as the FortiGate LAN interface (192.168.0.1). This can create an IP conflict or asymmetric routing issue:
It sounds like you’re dealing with a complex and possibly misconfigured network setup. Based on the description, here are some points to consider and investigate to pinpoint the issue and improve the setup:
It sounds like the management interface of the switch (192.168.0.2) might be causing routing or traffic issues if it's using the same subnet as the FortiGate LAN interface (192.168.0.1). This can create an IP conflict or asymmetric routing issue:
Thank you, the management interface was using the same subnet as the LAN interface on the Fortigate. The LAN on FG also had the trunk port of the switch. I unplugged the management interface and moved the subnet to a new vlan on the switch. Then set that vlan as the untagged vlan on the trunk interface and it seems to have completely resolved the issue.
User | Count |
---|---|
2534 | |
1351 | |
795 | |
641 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.