Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
svictor2
New Contributor

Fortiswitch - VRRP is not working with Standalone MCLAG-ICL

 

I am installing Standalone Fortiswitch FS-648F using MCLAG-ICL topology, critical issues were observed with VRRP and inter-VLAN routing functionality.

FS-SW-1 & FS-SW-2 connected through Port 55 & 56 as MCLAG-ICL link and all vlans allowed. 

L2 Vlans are 10,20,30,40,50
STP enabled and priority assigned as default. 
L3 vlan created and assigned IP's with VRIP 
FS-SW-1 is Master & FS-SW-2 Backup vrrp state
from FS-SW-1 Cli I am able to ping vrip for example 172.16.10.1 . (vlan 10)
When I ping from FS-SW-2 cli, i unable to ping vrip 172.16.10.1  (vlan10)

In sw-2 mclag-icl diag command output , it shows dormant role is SW-2. 
2nd switch is not responding for vrip 172.16.10.1 arp in MCLAG-ICL

Any solution for the issue ?
Is there any limitations with Fortiswitch VRRP with MCLAG-ICL ?

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hi,

 

 

To troubleshoot VRRP not working with standalone MCLAG-ICL, follow these steps:

  1. Enable VRRP Virtual MAC: Ensure that `vrrp-virtual-mac` is enabled for VRRP. This is crucial for VRRP operation.
  2. Configure VRRP Sessions: Configure two VRRP sessions on each SVI (Switched Virtual Interface). - Set VRRP priorities to ensure there is a VRRP master on each MCLAG core.
  3. Layer-3 Lookup: Verify that the layer-3 lookup for the VRRP virtual MAC address is enabled on the VRRP backup. This should be automatic.
  4. Check MCLAG and Trunk Hashing: Ensure that MCLAG and trunk hashing are correctly configured.

 

This allows ingress packets on the VRRP backup core to be routed without crossing the ICL if an appropriate route is available

Anthony-Fortinet Community Team.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors