Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sveinn
New Contributor II

Network Stability Issues with Fortigate 200E and MCLAG FortiSwitches

Hello,

I’m facing network stability issues post-adjustment in a Fortigate 200E and FortiSwitch environment and am looking for some troubleshooting assistance.

Setup Details:

  • Firewall: Fortigate 200E on FortiOS 7.2.6
  • Switches: 32 FortiSwitches on v7.2.5
  • Topology: Single connected switches with two central switches in an MCLAG configuration.
  • VLANs: 15 to 20 VLANs in use.

Issue: After any switch in the network is rebooted or disconnected, we experience packet drops for 15 to 40 seconds. The issue escalates with subsequent reboots or reconnections, causing packet drops for up to 15 minutes.

Recent Changes: We've implemented Spanning Tree Protocol (STP) enhancements to isolate Layer 2 domains and have set the MCLAG-pair to a root priority of 0 to maintain root status within the network modules. We're using Multiple Spanning Tree with instance 0 for all data VLANs and instance 15 for the management VLAN.

Questions: Could these STP changes be impacting our network stability? Do we need additional configuration given the number of VLANs we're managing?

Any insights or similar experiences would be greatly appreciated.

Thanks for your help.

4 REPLIES 4
dbu
Staff
Staff

Hi @Sveinn ,

From STP perspective if a switch goes down it looks it like a topology change and will take some time to recalculate and find the new best links. You can minimize this outage by implementing RSTP.

With RSTP you will have faster convergence of the network and the port will go only through three states : Discarding,Learning and Forwarding, spending less time.

 

 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Sveinn
New Contributor II

Hey @dbu 

Thanks for the suggestion! RSTP is already implemented in our network setup. We're still seeing these delays, though, which is puzzling. Any other settings in RSTP that might need tweaking to address these recalculations more efficiently?

Best regards!

dbu

Perhaps you can play with the forward-time. 

Have you implemented STP root guard ? If not have a look here :
Configuring STP settings | FortiSwitch Manager 7.2.2 | Fortinet Document Library

 

 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Sveinn
New Contributor II

Thank you for your suggestions!

Regarding the adjustment of the forward-time and the implementation of STP root guard, I appreciate your insights. However, I would like to mention that our network is set up using a FortiLink configuration where the FortiGate unit acts as the controller for the connected FortiSwitch units. Due to this setup, certain standard STP configurations, including STP root guard, are managed differently and may not be directly applicable in the same manner as in a standalone switch setup.

I will continue to explore other troubleshooting and configuration adjustments within the FortiLink environment to address the packet drop issues we're experiencing. Your suggestions have been helpful in broadening our troubleshooting approach, and I welcome any further recommendations or insights you might have, especially pertaining to FortiLink configurations.

Thank you once again!

Labels
Top Kudoed Authors