Hi to all!!
i setup my first ring topology and i am facing random internet disruptions. I have lots of experience on star topology.
I am using 2x FG-100F in HA with 2 ISPs. SD-WAN is using pinging to 8.8.8.8 for failover checks.
Ports 1 from each Firewall are connected to switch No1. Ports 13 from each Firewall are connected to switch No10. All 10 switches are connected with fiber cables in a ring mode. We are using Fortilink with type aggregate with split disabled. Fortlink includes ports 1 and 13 only.
What i am facing is random packet losses when i am pinging from any firewall to 8.8.8.8. If i disconnect the firewalls and connect my laptop with public ip configured, i have no losses. So, i don't think the ISP is an issue.
Note1: My FGs are using 7.0.16 FW and my FSs are using 7.4.2
Note2: I am not familiar with MCLAG and i don't know if it is needed here.
Hi
Split interface disabled means both interfaces are active, it is for ICL and is not supported on access switches like 124F and 148F. Which FSW model are you using?
On the other hand, here you are using 10 FortiSwitches, I'm not sure you can use ICL with more than 2 switches. You need to check this as well.
I think you want to enable split interface, so it uses ISL instead of ICL, and all should be fine.
Hi!! thank you for your answer. On the datasheet here, on the 4th page it mentions "Active-Active Split LAG from FortiGate to FortiSwitches for Advanced Redundancy" is supported on 1xx series switches. Yes i am using 124F.
Last Friday, we tried enabling the split interface without success however it is truth that we see 3 different symptoms which might be different problems so situation can become confused.
Symptom A. Losing random packets when i ping 8.8.8.8 from Firewall A. I don't lose when i ping from Firewall B. Note that both lines tested without Firewall and we don't lose packets.
Symptom B. Losing random packets when i ping Firewall A from a cloud monitoring system.
Symptom C. Losing internet for 15 minutes randomly 2-3 times per month. In this case we don't know if we actually lose internet or local network which results our machines to lose internet.
Hi
I'm not sure to understand what is Active-Active split LAG. But one thing I'm sure is that 124F does not support MCLAG, so it does only support split interface.
Please check the feature matrix here:
So please enable split interface and redo the tests.
In case firewall A has some ping lose and not firewall B, then I've seen similar cases where the related Ethernet cable of firewall A was defective.
On the other hand, what is the version of you FortiOS and FortiSwitche firmware? And are all FortiSwitches at the same firmware version?
Also please attach a diagram showing the connectivity of your firewalls, switches, and internet.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1747 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.