Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
darrencarr
New Contributor II

Fortigate VLAN interfaces

I am trying to configure to Internet connections into my Fortigate device. I have two Fortigate in HA (60B in my lab). I have configured VLAN interfaces off WAN2 (ISP1-VLAN16, ISP2-VLAN19). I am trying to test out the whole process of aging out the MAC-ADDRESS on my switch that the Fortigates are patched into age out should the ISP link go down. I have dead gateway detection configured in the firewall and the route disappears when I disconnect one of the ISP links and the traffic fails over after a period of time. I was also hoping to see the MAC-ADDRESS disappear out of my switch for completeness and come back when the interface (ISP link) was re-establised. The MAC address never goes though as the Admin Status of the VLAN interface on the Fortigate remains up. Is there any way you can get the VLAN interface to go ' Admin down' other than doing this manually? I now its not a big issue as the traffic gets routed via the other ISP link. Also, when a link fails and the traffic is re-routed, when the link comes back online why does the traffic revert back to the old link (previously failed link) and not stay on the link it failed over to? Thanks Darren
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
7 REPLIES 7
emnoc
Esteemed Contributor III

Things to think about; The aging timer is set and configured on the L2 siwtch. Cisco defaults to 300secs and if the layer2 port goes down, those address should be expired on that specific switch. The admin status of the vlan interface on the FGT will always be up if the pyshical link is up. Are you pulling the actual FGT layer1 link or doing something else to mimic your failure?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
darrencarr
New Contributor II

Hi The timer on my switch is set for 5 minutes. If I remove the patch from my ISP into my switch (disconnect cable) the MAC-ADDRESS eventually ages out. The Fortigate VLAN interface however stays up? I guess I don' t need to worry about this as the actual outgoing interface (MAC-ADDRESS that has been aged out to get out to the NET) as actually been removed and the route also removed from the routing monitor.
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
darrencarr

One other question I have regarding this failure.... When I simulate the failure (i.e. remove the patch lead from the switch) the following happens: - dead peer detected - route is removed from routing monitor - http PING intialized before cable removed eventually times out - traffic being routed over the link is routed over the other ISP after approximately 32 seconds Which is all good... however when I re-establish the connectivity (i.e. patch the lead back into the switch) the traffic is re-routed over the restored link, despite it just coming back online and both links being of an equal cost? Seems a bit dangerous to me if a link was going up and down due to a configuration or hardware problem? Can anyone explain why it does this? Thanks
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
darrencarr
New Contributor II

Also.. You can kind of see what I am trying to do here with the network diagram http://support.fortinet.com/forum/m.asp?m=54841&p=1&tmode=1&smode=1
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
emnoc
Esteemed Contributor III

If I remove the patch from my ISP into my switch (disconnect cable) the MAC-ADDRESS eventually ages out. The Fortigate VLAN interface however stays up?
That' s normal and expected. The DEAD-GW DETECT does drop the interface vlan. If your worried about equal-cost routes, than set the backup as a higher cost to begin with.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
darrencarr
New Contributor II

Hi Thanks for the information. I had tested and documented this in my lab. I am happy with the equal cost routes, thats what I am trying to achieve. Do you know why though if I drop one of the links, the traffic then goes over the other link, but then when the link is re-established is goes back over the link that went down? I can' t find any documentation relating to this?
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
brianmac64

Interface priorities? I believe they can be set via the cli
moo?
moo?
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors