I'm still looking for a configuration guide and best practices for setting up a FortiGates cluster with a core based on two 1024E FortiSwitches in an MCLAG. I'm having the problem that when connecting access switches in a ring topology, the ring closure process begins to be negotiated even on the ICL interface of the MCLAG.
Any help on this?
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hi fasoli,
We are still trying to get you an answer or help. We will respond as soon as possible.
this kind of issues are hard to troubleshoot over a community discussion, I would recomend to no close any ring before performing a LLDP lockdown and a fabric lockdown.
STP Transitions mess with Fortlink Automatization while forming automatic ISL trunks, so it is best to let Fortilink build main network links automatically, then perform lockdowns, it makes network stable and disable Fortilink autolink trunk discovery. then if desire to use ring topology to enable some redundant links you can do it by turning on auto-isl-lldp profile only on needed basics over ports forming those links.
details can be consulted on follwing links and documentation
For specific recomendations about your enviroment you should open a TAC ticket.
Please be adivised about TAC scope of work when contacting a TAC engineer.
hope it helps
| User | Count |
|---|---|
| 2727 | |
| 1416 | |
| 810 | |
| 738 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.