Hi all,
I'm trying to create a LAG between a virtual fortigate appliance and two 3650 cisco switches.
EDGE1 EDGE2
\ /
\ /
\ /
Fortigate
My configuration works correctly singularly however, when i try and aggregate the ports, i get the following
1 Aggregated port works fine. 1 does not
Number of channel-groups in use: 1 Number of aggregators: 1
Group Port-channel Protocol Ports ------+-------------+-----------+----------------------------------------------- 1 Po1(SU) LACP Gi0/1(P)
EDGE1#
Number of channel-groups in use: 1 Number of aggregators: 1
Group Port-channel Protocol Ports ------+-------------+-----------+----------------------------------------------- 1 Po1(SN) LACP Gi0/1(w) <-- waiting to be aggregated
EDGE2#
FW1 # diagnose netlink aggregate name External LACP flags: (A|P)(S|F)(A|I)(I|O)(E|D)(E|D) (A|P) - LACP mode is Active or Passive (S|F) - LACP speed is Slow or Fast (A|I) - Aggregatable or Individual (I|O) - Port In sync or Out of sync (E|D) - Frame collection is Enabled or Disabled (E|D) - Frame distribution is Enabled or Disabled
status: up ports: 2 link-up-delay: 50ms min-links: 1 ha: master distribution algorithm: L4 LACP mode: active LACP speed: slow LACP HA: enable aggregator ID: 1 actor key: 17 actor MAC address: fa:16:3e:7e:a4:5f partner key: 1 partner MAC address: 5e:00:00:00:80:00
slave: port2 link status: up link failure count: 0 permanent MAC addr: fa:16:3e:7e:a4:5f LACP state: established actor state: ASAIEE actor port number/key/priority: 1 17 255 partner state: ASAIEE partner port number/key/priority: 2 1 32768 partner system: 32768 5e:00:00:00:80:00 aggregator ID: 1 speed/duplex: 1000 1 RX state: CURRENT 6 MUX state: COLLECTING_DISTRIBUTING 4
slave: port3 link status: up link failure count: 0 permanent MAC addr: fa:16:3e:03:45:1c LACP state: negotiating actor state: ASAODD actor port number/key/priority: 2 17 255 partner state: ASAIDD partner port number/key/priority: 2 1 32768 partner system: 32768 5e:00:00:01:80:00 aggregator ID: 2 speed/duplex: 1000 1 RX state: CURRENT 6 MUX state: WAITING 2
I've notcied they've both got different aggregator ID's ?
I was going to ask is there any limitation on which ports to use but they work singularly or when configured into two separate LAGS but not when they are aggregated.
I've tried shuting the ports down and bringing up one at a time, made sure physical interface configuration on cisco was done first with all switchport commands added before enabling the channel group.
Anyone have an input?
Cheers,
RD
According to below 3560s are not stackable and without it you can't set up an etherchannel between them.
Are these 2x sw-cisco in a stack? If not, than no you can do what your asking and that's why you have different aggr-id
Ken
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.