Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nflnetwork29
New Contributor III

fortiswitch spanning tree mode MSTP

we have two main switches configured in MC-LAG. Call it Fortiswitch A/B.

 

In a spanning tree config would they both have identical priority? or would A be 4096 and B 8192 for example?

 

What about if they are managed by the FortiGate. Does the FortiGate need to be the root? Can you set the spanning tree priority on the FortiGate itself?

 What is the best practices here?

 

 

Thanks, 

3 REPLIES 3
sjoshi
Staff
Staff

In a Multiple Spanning Tree Protocol (MSTP) configuration with two main switches in MC-LAG, it is recommended to set different priorities for redundancy. For example, you can set FortiSwitch A with a priority of 4096 and FortiSwitch B with a priority of 8192 to establish a hierarchy. When managed by a FortiGate, the FortiGate does not need to be the root bridge, but you can set the spanning tree priority on the FortiGate itself to influence the spanning tree topology. Best practice is to configure the priorities strategically to ensure a stable and efficient spanning tree network, considering factors like redundancy, network performance, and fault tolerance.

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
nflnetwork29
New Contributor III

FortiGate does not "need" to be the root bridge? But should it?

What is best practice? Leave FortiGate with default priority? disable spanning tree on FortiGate all together?

sachitdas_FTNT

In MCLAG-ICL topology, both the core FSWs will act as root Bridge. Both FSWs will have MCLAG mac address that will act as root Bridge mac address.

Please refer below links:-

https://community.fortinet.com/t5/FortiSwitch/Technical-Tip-Spanning-tree-in-LAG-and-MCLAG/ta-p/3478...

https://docs.fortinet.com/document/fortiswitch/7.6.0/fortiswitchos-administration-guide/860027/mclag

 

From the STP treeʼs point of view, the MCLAG switches should not present themselves differently as a single MCLAG dual-homed virtual switch (accessed through an MCLAG trunk) and as a pair of STP running switches (accessed through asymmetric individual ports, typically in a ring topology). For example, the spanning tree with its root bridge outside of the MCLAG switches cannot connect to it through a dual-homed trunk on one side, while connecting to the MCLAG switches with asymmetric ports at the same time. Such configurations present a mixed view of the MCLAG switches to the STP instance and are not supported.

 

 

 

Regards,
Sachit Das
ETAC Engineer
Wifi-Switching – International Support
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors