Hello,
I’m facing network stability issues post-adjustment in a Fortigate 200E and FortiSwitch environment and am looking for some troubleshooting assistance.
Setup Details:
Issue: After any switch in the network is rebooted or disconnected, we experience packet drops for 15 to 40 seconds. The issue escalates with subsequent reboots or reconnections, causing packet drops for up to 15 minutes.
Recent Changes: We've implemented Spanning Tree Protocol (STP) enhancements to isolate Layer 2 domains and have set the MCLAG-pair to a root priority of 0 to maintain root status within the network modules. We're using Multiple Spanning Tree with instance 0 for all data VLANs and instance 15 for the management VLAN.
Questions: Could these STP changes be impacting our network stability? Do we need additional configuration given the number of VLANs we're managing?
Any insights or similar experiences would be greatly appreciated.
Thanks for your help.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @Sveinn ,
From STP perspective if a switch goes down it looks it like a topology change and will take some time to recalculate and find the new best links. You can minimize this outage by implementing RSTP.
With RSTP you will have faster convergence of the network and the port will go only through three states : Discarding,Learning and Forwarding, spending less time.
Hey @dbu
Thanks for the suggestion! RSTP is already implemented in our network setup. We're still seeing these delays, though, which is puzzling. Any other settings in RSTP that might need tweaking to address these recalculations more efficiently?
Best regards!
Perhaps you can play with the forward-time.
Have you implemented STP root guard ? If not have a look here :
Configuring STP settings | FortiSwitch Manager 7.2.2 | Fortinet Document Library
Thank you for your suggestions!
Regarding the adjustment of the forward-time and the implementation of STP root guard, I appreciate your insights. However, I would like to mention that our network is set up using a FortiLink configuration where the FortiGate unit acts as the controller for the connected FortiSwitch units. Due to this setup, certain standard STP configurations, including STP root guard, are managed differently and may not be directly applicable in the same manner as in a standalone switch setup.
I will continue to explore other troubleshooting and configuration adjustments within the FortiLink environment to address the packet drop issues we're experiencing. Your suggestions have been helpful in broadening our troubleshooting approach, and I welcome any further recommendations or insights you might have, especially pertaining to FortiLink configurations.
Thank you once again!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1709 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.