Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
blackstark
New Contributor II

LACP between Cisco and Fortiswitch (MC-LAG) STP error

i have a created a new trunk group on the fortiswitcch

mc-lag enabled, STP Enable , Edge port

lacp active 

port 48,port48

Cisco

LACP mode active

Port channel 13

Cisco switch is running MST spanning tree mode (same as fortiswitch) 

when i try to enable to port-channel i get STP error on the cisco side and the cisco ports go into err-disabeld state 

 

any idea what going on?

does anyone have a working configuration of a similar environment?

6 REPLIES 6
anignan
Staff
Staff

Hi @blackstark ,

Can you try disabling edge port and mclag on fortiswitch? I dont think you need them.

 

Thanks

blackstark
New Contributor II

it's up now. so one side is passive and the cisco side is active is the recommended approach? I always thought they should match on both side. 

 

i disable edge port

 

for mc-lag - is this required because I am spanning across a 2 FSW. 

ebilcari

It's not mandatory to match but it should work with both nodes being active (maybe Cisco doesn't like the Fortinet LACP PDU), anyway having one side configured as active does the job fully since it still puts the problematic port immediately down and not cause any packet drops. Both nodes set as passive will not work and having static it's prone to packet drop since the other node is not aware if the link is not useful anymore.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
anignan
Staff
Staff

Hi @blackstark ,

 

I think MCLAG is to have 1 logical FSW with 2 physical via an ICL link. I may be missing something..

 

REF: https://docs.fortinet.com/document/fortiswitch/7.2.5/administration-guide/860027/mclag

 

Abdel

 

anignan

Hi @blackstark ,

 

Ah sorry my bad i misread it if you are spanning with 2 FSW you  need MCLAG i thought you said MCLAG to the cisco switch. 

Good to disable edge port because this is the same as portfast which disable STP

 

Thank

fp1
New Contributor II

Have read somewhere:

 

On both FortiSwitches you have to change the STP announcement type from both to single.

Set to both to allow both core switches of an MCLAG to transmit STP BPDUs. Set to single to prevent both core switches of an MCLAG from transmitting STP BPDUs.

 

Log into the switch CLI and put this in...

 

config switch stp setting
set mclag-stp-bpdu single
end

On Cisco Side looks like:

 

*Jan 19 10:35:46.535: %SPANTREE-5-ROOTCHANGE: Root Changed for instance 0: New Root Port is Port-channel12. New Root Mac Address is 8439.1234.567a
*Jan 19 10:35:46.552: %SPANTREE-5-TOPOTRAP: Topology Change Trap for instance 0
*Jan 19 10:37:11.637: %PM-4-ERR_DISABLE: channel-misconfig error detected on Po12, putting Gi1/0/1 in err-disable state
*Jan 19 10:37:11.659: %PM-4-ERR_DISABLE: channel-misconfig error detected on Po12, putting Gi2/0/1 in err-disable state
*Jan 19 10:37:11.706: %PM-4-ERR_DISABLE: channel-misconfig error detected on Po12, putting Po12 in err-disable state
*Jan 19 10:37:12.639: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/1, changed state to down

Labels
Top Kudoed Authors