Good morning!
How does static mode work in LACP on Fortigate?
As far as I know, Fortigate don't send lacp messages in static mode,
so how can I communicate in a static-static configuration?
Thank you
Solved! Go to Solution.
Hi Jin-Gyu,
LACP offers two dynamic modes, "active" and "passive," which use LACP messages to negotiate and form an aggregate link.
When a FortiGate is configured with "static" LACP mode, the interface acts as a simple trunk, and all ports in the LAG will participate in traffic transmission. This means that if the FortiGate has "static" LACP mode enabled and a peer device also has LACP enabled (active or passive), the connection will not come up, as LACP negotiation is not occurring.
The "static" mode is often used when a peer device on the other end of the LACP link does not support LACP or when you want to force a specific set of ports into the LAG without relying on LACP negotiation. For example, when connecting two FortiGate units in an LACP configuration, you might choose "static" mode if LACP is not needed between them.
Please refer to the documents below for more information:
If you have found a solution, please like and accept it to make it easily accessible to others.
Regards,
Aman
For all others reading this post, to prevent confusion - there is no such thing "static LACP" in Fortigate (or anywhere for that matter), only, as @kaman pointed "active" or "passive", "static" (confusingly also named as a lacp mode) means do aggregate interfaces but disable LACP completely on them.
Hi Jin-Gyu,
LACP offers two dynamic modes, "active" and "passive," which use LACP messages to negotiate and form an aggregate link.
When a FortiGate is configured with "static" LACP mode, the interface acts as a simple trunk, and all ports in the LAG will participate in traffic transmission. This means that if the FortiGate has "static" LACP mode enabled and a peer device also has LACP enabled (active or passive), the connection will not come up, as LACP negotiation is not occurring.
The "static" mode is often used when a peer device on the other end of the LACP link does not support LACP or when you want to force a specific set of ports into the LAG without relying on LACP negotiation. For example, when connecting two FortiGate units in an LACP configuration, you might choose "static" mode if LACP is not needed between them.
Please refer to the documents below for more information:
If you have found a solution, please like and accept it to make it easily accessible to others.
Regards,
Aman
Thank you for your kind answer.
Can I ask you one more question?
If use lacp-mode static because the peer equipment does not support lacp, it seems similar to use h/w switch or s/w switch instead of LAG. Is there a reason why fortigate exist lacp-mode static?
I'm sorry for bothering you.
For all others reading this post, to prevent confusion - there is no such thing "static LACP" in Fortigate (or anywhere for that matter), only, as @kaman pointed "active" or "passive", "static" (confusingly also named as a lacp mode) means do aggregate interfaces but disable LACP completely on them.
Thank you for answer.
I misunderstood because it was in the same 'set lacp-mode'.
Yes, it is indeed confusing they (Fortinet) list it as a kind of LACP mode when they mean to disable LACP altogether.
User | Count |
---|---|
2597 | |
1382 | |
801 | |
663 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.