Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
seth57
New Contributor

Unable to connect 92D on a Juniper switch - MAC learning issue

Hi all

 

i just bought a 92D to replace my 60D

I converted config file to match new hardware and connected it to Juniper switch but nothing worked

I searched what could be wrong on fortigate but all seems to be OK

On switch side, i saw that when internal1 was connected ( only this port connected to the switch ), MAC address was correctly learnt on the switch port but when internal2 was connected, MAC of internal1 disappeard from the switch and i could only see the MAC of internal2

At this instant, my 60D is working perfectly on this switch so i think that the problem does not come from the switch

are you aware about this kind of problem ?

Is there any parameter to set up ?

 

Thanks in advance

 

NSE6

NSE6
1 Solution
emnoc
Esteemed Contributor III

What's the cfg like for the access port and are you sure  your not mistaking   STP blocking or BPDU filters on the juniper?  And what's your topology and reason for connecting the 2 internals? And are you running these 2 ports in the same STP domain ? And do you have STP enable on the fortigate?

 

 

You can check via the EX cmds for port blocked by STP;

 

show spanning-tree interface terse

show ether-switch table

 

 

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
12 REPLIES 12
seth57
New Contributor

Hello

 

Sorry for delay, i was not able to perform tests

I can see now that the MAC of the cisco switch is learned by the juniper switch via Fortigate interfaces ...

 

I will try to find out what can be the command to solve this

 

BR

NSE6

NSE6
emnoc
Esteemed Contributor III

So do you have the FGT92D connected directly to the EX or thru a cisco switch?

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
seth57
New Contributor

Cisco switch is connected to wan1 and all other interfaces to EXswitch

Cisco and EX are connected but MAC address of the cisco switch is learnt via FGT ...

NSE6

NSE6
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors