Hi,
I set up a szenario as decribed here:
- i have two FortiGates in Active/Passive Mode
- 5 FS-124G-FPOE switches in a ring config
- Active Fortigate connects X1 to switch 1 und X2 to switch 5
- Passive Fortigate connect X1 to Switch 1 and X2 to switch 5
- X1 and X2 defined as Fortlink Split interface
It's all working fine if on both firewalls X1 is active. However, after a reboot or HA failover, I sometimes encounter the following situation:
- Active Fortigate - X1 is active on the Fortlink
- passiv Fortigate - X2 is active on the Fortilink
In this situation several clients are not reachable until I manual unplugg passive fortigate X2 so that it switches to X1
Fortigates are an 7.4.9 and FortiSwitch 7.6.6
Do you have by any change Blocking intra-vlan enabled on the client vlan?
I have a similar problem, but I'm not using split interface. But the problem looks the same.
We are now looking with suport into this problem, we are using FortiGate 7.4.9 and FortiSwitch 7.6.4.
We found out with support that the issue is related when intra-vlan blocking is enabled.
Yes I have the intra-vlan blocking option enabled on some of my vlans - i will have a look an that - thanks for the hint
Created on ‎01-15-2026 10:24 AM Edited on ‎01-15-2026 10:25 AM
Where you able to look into this? Do you have a support case for this?
Just checking because mine support case is really taking some time now.
Kind regards
It's a Fortigate 121-G with FS-124G FPOE
Mine is Foritgate 601F with FS-1024E in MCLAG as core and 2 x FSR-216F-POE in a ring attached to the core.
I think the problem here is not related to the fact that X2 is enabled after fail-over instead of X1, but to the fact that it does work with X1 and doesn't with X2.
To confirm this, try unplug X1 from both FGTs (leave only X2 on both) and perform a couple of fail-over test to check if all hosts are reachable.
Ensure that the cluster is synced before each fail-over test.
I have tested this.
- If active and passive firewall are on X1 everthing is working
- if active and passive firewall are on X2 everything is working
This bevahior is only when one Firewall is on X1 and the other is on X2.
Do you have a cable connecting SW1 to SW5 to complete the L2 ring? This is required in the linked topology.
| User | Count |
|---|---|
| 2910 | |
| 1451 | |
| 850 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.