Community,
I have the below:
2 fortigate 200F ( HA cluster active active 1st is primary and 2nd is secondary) connected to a core switch with 2 connection each firewall ( 4 connection in total).
the issue is when i try to test the HA active active and I remove the forti primary connection with the core switch, I have no access to the secondary forti ( cannot ping over the ip address that I gave for the both 200F).
The configuration in the core switch is with port channel (channel group) mode active and in the forti is 802.3ad aggregate.
Please Help.
Kind regards
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @firas ,
Any HA deployment highly depend on the network design. Based on behavior, looks like your network only works on the primary unit. When primary down, the network itself did not failover to the secondary unit.
And you did mentioned about 2 ports suspended in ethernet channel. I believe it suspended on the switch level to prevent looping. Which may triggered by Spanning Tree Protocol.
This link may be helpful to help you troubleshoot on the issue:
https://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=FD50620
https://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=FD47572
To add to this, I found that I have 2 ports suspended in the ethernet channel for the secondary forti.
Hi @firas ,
Any HA deployment highly depend on the network design. Based on behavior, looks like your network only works on the primary unit. When primary down, the network itself did not failover to the secondary unit.
And you did mentioned about 2 ports suspended in ethernet channel. I believe it suspended on the switch level to prevent looping. Which may triggered by Spanning Tree Protocol.
This link may be helpful to help you troubleshoot on the issue:
https://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=FD50620
https://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=FD47572
Thank you for your reply. I followed the below link and it solved my problem.
Technical Tip: Aggregate link configuration topolo... - Fortinet Community
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.