Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fasoli
New Contributor

STP IN FORTILINK RECOMMENDED CONFIGURATION

I'm still looking for a configuration guide and best practices for setting up a FortiGates cluster with a core based on two 1024E FortiSwitches in an MCLAG. I'm having the problem that when connecting access switches in a ring topology, the ring closure process begins to be negotiated even on the ICL interface of the MCLAG.

Any help on this https://100001.onl/ ?

3 REPLIES 3
Stephen_G
Moderator
Moderator

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen - Fortinet Community Team
Stephen_G
Moderator
Moderator

Hi fasoli,

 

We are still trying to get you an answer or help. We will respond as soon as possible.

Stephen - Fortinet Community Team
Adolfo_Z_H
Staff
Staff

this kind of issues are hard to troubleshoot over a community discussion, I would recomend to no close any ring before performing a LLDP lockdown and a fabric lockdown.

 

STP Transitions mess with Fortlink Automatization while forming automatic ISL trunks, so it is best to let Fortilink build main network links automatically, then perform lockdowns, it makes network stable and disable Fortilink autolink trunk discovery. then if desire to use ring topology to enable some redundant links you can do it by turning on auto-isl-lldp profile only on needed basics over ports forming those links.

 

details can be consulted on follwing links and documentation

 

https://community.fortinet.com/t5/FortiSwitch/Technical-Tip-Enable-lock-down-topo-lldp-profile-on-ma...

 

https://community.fortinet.com/t5/FortiSwitch/Troubleshooting-Tip-Lockdown-LLDP-Profile-error-for-Fo...

 

https://docs.fortinet.com/document/fortiswitch/7.6.4/fortilink-guide/173272/optimizing-the-fortiswit...

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Lockdown-ISL-remain-enabled-even-disabling...

 

For specific recomendations about your enviroment you should open a TAC ticket.

Please be adivised about TAC scope of work when contacting a TAC engineer.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enhance-support-experience-with-TAC...

 

hope it helps

Secure Access Team LATAM TAC
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors