Hi,
I set up a szenario as decribed here:
- i have two FortiGates in Active/Passive Mode
- 5 FS-124G-FPOE switches in a ring config
- Active Fortigate connects X1 to switch 1 und X2 to switch 5
- Passive Fortigate connect X1 to Switch 1 and X2 to switch 5
- X1 and X2 defined as Fortlink Split interface
It's all working fine if on both firewalls X1 is active. However, after a reboot or HA failover, I sometimes encounter the following situation:
- Active Fortigate - X1 is active on the Fortlink
- passiv Fortigate - X2 is active on the Fortilink
In this situation several clients are not reachable until I manual unplugg passive fortigate X2 so that it switches to X1
Fortigates are an 7.4.9 and FortiSwitch 7.6.6
Do you have by any change Blocking intra-vlan enabled on the client vlan?
I have a similar problem, but I'm not using split interface. But the problem looks the same.
We are now looking with suport into this problem, we are using FortiGate 7.4.9 and FortiSwitch 7.6.4.
We found out with support that the issue is related when intra-vlan blocking is enabled.
I think the problem here is not related to the fact that X2 is enabled after fail-over instead of X1, but to the fact that it does work with X1 and doesn't with X2.
To confirm this, try unplug X1 from both FGTs (leave only X2 on both) and perform a couple of fail-over test to check if all hosts are reachable.
Ensure that the cluster is synced before each fail-over test.
| User | Count |
|---|---|
| 2880 | |
| 1446 | |
| 843 | |
| 822 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.