Hello, Fortinet newbie here.
I am trying to migrate our campus network from a collapsed Dell core on S series switches to a Fortinet core with two Fortigate 601F in HA and two FortiSwitch 2048 in MCLAG. My plan is set up VRRP on the FG601 to join the production network and eventually make the HA the primary router and take over the network.
After I created the vlans and VRRP, like this:
FortiGate-601F # config system int
I get an extra static route for every VRIP along with the directly connected subnet in that vlan:
FortiGate-601F # get router info routing-table all
...
C 172.16.4.0/24 is directly connected, VLAN4
C 172.16.4.1/32 is directly connected, VLAN4
C 172.16.5.0/24 is directly connected, VLAN5
C 172.16.5.1/32 is directly connected, VLAN5
...
I have never noticed this kind of extra host routes on other platforms. Is it normal?
Thank you very much for your input.
hi,
quite strange that both VRRP IPs appear in RIB. i have several setups with VRRP but none show it.
try set vrrp-virtual-mac enable and see if anything changes.
I set vrrp-virtual-mac enable under interface VLAN4 and VLAN5. But that didn't remove the VRRP IPs in RIB. And I found I lost connection to or from VLAN5 after that because I had been using my desktop in VLAN5 to remote control a wireless laptop in VLAN7 which has a direct cable connection to the Mgmt port of the new Fortigate in the data center. I walked over to the data center and got on that laptop. I couldn't ping any device in VLAN5 from there. The fortigate could see lots of devices on the production network, meaning the trunk between the production core and the new Fortinet 2048 core switch is working and passing vlan traffic.
To get routing back for Vlan 4 and 5, I had to remove "set vrrp-virtual-mac enable", disconnected and reconnected the trunk link.
So now my real issue is VRRP not working as expected. "get router info vrrp" shows that the Fortigate is the Master router for all of the vlans as opposed to the Backup router, while "show vrrp brief" on the Dell S4128 core switch with OS10 shows it's still the master router for all of the production vlans and doing its job, as long as I don't "set vrrp-ritual-mac enable" on any vlan on the Fortigate.
I noticed in Local in Policy, under "Network provide" group, there is VRRP accepted only on Source Interface Vlan 2. I wonder if it's blocking VRRP on all the other vlans. But I can't find a place to change that to source interface Fortilink. And even in Vlan2, the Fortigate thinks it's the master with priority 25. The Dell has priority 50. So, they are not really talking to each other any way.
I verified Both sides are running version 2. VRRP group ID is the same as the vlan number. But I am beginning to think the Dell group id may not be the VRGRP in FortiOS.
User | Count |
---|---|
2534 | |
1351 | |
795 | |
641 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.