Hi all
I have an issue with a MAC-ADDRESS flapping in my network on one of the routers that links two of our sites. The MAC-ADDRESS that is flapping is the virtual MAC-ADDRESS of physical port that is patched into the switch at site two (right hand side as you look at the diagram).
At each site there are two Fortigate 1000A running in an A-P cluster. HA enabled on port 10.
At the HQ site Port 8 of the firewall is configured with three vlan interfaces 32, 1030, 1332. A trunk connection then links the firewalls to the DMZ switches. The trunk is configured to carry these VLANs only.
For redundancy VLAN1030 (WAN link to DR site) is patched into port 34 on DMZSWITCH1, VLAN1332 (WAN link to DR site) is patched into port 33 on DMZSWITCH2. Both are configured as access ports.
At the DR site Port 8 of the firewall is configured with three vlan interfaces 32, 1030, 1332. I currently have a single point of failure with the switch which will be resolved next week. Currently port 4 of the switch is an acess port in vlan 1029, port 7 is an access port in vlan 1332 and ports 5 and 6 are configured as trunk ports carrying these vlans only. There is a difference in vlans for vlans 1029, vlan1030 (the tag is removed by the isp as it passes over the link). This link is operating just fine. I have a problem with the VLAN1332 link in that INT4 is showing that the link is flapping the MAC-ADDRESS is that of the Fortigate.
I have adjusted the GROUP_ID of the clusters so this is not causing the issue.
Can anyone advise? I am struggling here?
Thanks
Fortigate 1000A
v4.0,build194,100121 (MR1 Patch 4)
Fortianalyzer 800B
v4.0,build0130 (MR1 Patch 3)