Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rcpdkc
Contributor II

Fortigate Same Mac Address

I have 2 firewalls, lan and wan. there is also 1 cisco backbone in between. my problem is this: when I make 802.3ad from 1g 2 fiber ports of the firewall, the connection between 2 firewalls is provided. However, when I do 802.3ad with 10g, there is no connection between the two firewalls. The part I pay attention to is this. When I make 802.3ad in 1g connection, the mac address is different in 2 ports. However, when I do 802.3a with 10g, the virtual mac address on 2 ports is the same and only one device appears in the mac address table of the backbone. what is the reason for this?

 

WhatsApp Image 2024-02-06 at 17.55.04.jpegWhatsApp Image 2024-02-06 at 17.55.04 (1).jpeg

5 REPLIES 5
AEK
Honored Contributor II

I don't know why such LACP interface has this kind of MAC, but you should fix it by changing the MAC address with the below command to avoid MAC conflict:

 

conf sys interface

  edit WAN

    set macaddr xx:xx:xx:xx:xx:xx

  end

AEK
AEK
rcpdkc
Contributor II

This command does not work

smaruvala

Hi,

 

- Are the LAN and WAN firewalls are part of 2 different HA cluster? The MAC address looks same as the virtual MAC address of the interface as Hex value of 12 is nothing but 18 in integer terms which is your interface in the port channel.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-HA-Cluster-virtual-MAC-addresses/ta-p/1942...

 

Regards,

Shiva

rcpdkc

Yes, there are 2 different Ha clusters, so how do I solve this problem? Since the same mac address appears on the backbone, the connection is not established

smaruvala

Hi,

 

One of the component in the virtual MAC calculation is the group ID of the HA. You can change the HA group IP of either the plan HA cluster of the WAN HA Cluster so that the virtual MAC will change. Please make sure you make these changes during the downtime or change window

Please refer the below links.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-A-conflict-HA-virtual-MAC-address-in-the-d...

https://docs.fortinet.com/document/fortigate/7.4.2/administration-guide/564710/cluster-virtual-mac-a...

 

Regards,

Shiva

Labels
Top Kudoed Authors