Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tobisfr
New Contributor III

HA Fortigate managing a stack of several FortiSwitch units ( NON-MCLAG)

Hi,

 

I set up a szenario as decribed here:

HA-mode FortiGate units managing a stack of several FortiSwitch units | FortiSwitch 7.6.4 | Fortinet...

 

- i have two FortiGates in Active/Passive Mode

- 5 FS-124G-FPOE switches in a ring config

- Active Fortigate connects X1 to switch 1 und X2 to switch 5

- Passive Fortigate connect X1 to Switch 1 and X2 to switch 5

- X1 and X2 defined as Fortlink Split interface

 

It's all working fine if on both firewalls X1 is active. However, after a reboot or HA failover, I sometimes encounter the following situation:

- Active Fortigate - X1 is active on the Fortlink

- passiv Fortigate - X2 is active on the Fortilink

 

In this situation several clients are not reachable until I manual unplugg passive fortigate X2 so that it switches to X1

 

Fortigates are an 7.4.9 and FortiSwitch 7.6.6

9 REPLIES 9
sj3fk3
New Contributor

Do you have by any change Blocking intra-vlan enabled on the client vlan?

 

I have a similar problem, but I'm not using split interface. But the problem looks the same. 

We are now looking with suport into this problem, we are using FortiGate 7.4.9 and FortiSwitch 7.6.4. 

 

We found out with support that the issue is related when intra-vlan blocking is enabled. 

 

 

tobisfr
New Contributor III

Yes I have the intra-vlan blocking option enabled on some of my vlans - i will have a look an that - thanks for the hint

sj3fk3
New Contributor

Where you able to look into this? Do you have a support case for this? 

 

Just checking because mine support case is really taking some time now. 

 

Kind regards

 

 

HarryTran
Staff
Staff

Hi @tobisfr and @sj3fk3 

 

May I know what the FortiGate model, I will try to reproduce the issue on my lab.

 

Thanks.

Harry

tobisfr
New Contributor III

It's a Fortigate 121-G with FS-124G FPOE

sj3fk3

Mine is Foritgate 601F with FS-1024E in MCLAG as core and 2 x FSR-216F-POE in a ring attached to the core. 

AEK
SuperUser
SuperUser

I think the problem here is not related to the fact that X2 is enabled after fail-over instead of X1, but to the fact that it does work with X1 and doesn't with X2.

To confirm this, try unplug X1 from both FGTs (leave only X2 on both) and perform a couple of fail-over test to check if all hosts are reachable.

Ensure that the cluster is synced before each fail-over test.

AEK
AEK
tobisfr
New Contributor III

I have tested this.

- If active and passive firewall are on X1 everthing is working

- if active and passive firewall are on X2 everything is working

 

This bevahior is only when one Firewall is on X1 and the other is on X2. 

brandonziots
New Contributor II

Do you have a cable connecting SW1 to SW5 to complete the L2 ring? This is required in the linked topology. 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors