Good morning everyone,
We have a Fortigate cluster, members model 200F.
Recently, we had to move one of the two members to a secondary data center.
We then performed a failover test, and everything worked correctly except for one interface; we can no longer reach any hosts connected to this interface from the recently moved member.
The problematic interface is a LAG (Link Aggregation Group) of two ports, connected to a core switch.
This interface serves a dmz network.
It's an active-passive cluster, and I don't have much availability for maintenance windows due to having users in different time zones. Therefore, I am struggling to troubleshoot the currently passive member.
If I try to run a traceroute without options on a host in the DMZ network, I get a response, but with three hops, the second hop, I suspect, is the active member.
If I set "execute traceroute-options device dmz" and try to run "execute traceroute 10.0.0.10," I get "1 traceroute: sendto: Network is unreachable
It even fails if i run "execute traceroute 10.0.0.1" which is the dmz gateway.
I tried then to traceroute from a known working network, same traceroute steps, from the passive member, they fail the same exact way, i am completely lost on how i should troubleshoot this type of problem.
Can somebody point me in the right direction?
Hi Sassoli, given that the devices are in DC, they are strategically important devices. It's best to create a TAC case.
Thanks,
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.