← Back to knowledge base
highHA & Clustering

Troubleshooting intermittent traffic and failover issues in a FortiGate HA deployment

Confirmed 7/30/2026

Problem

A FortiGate high-availability deployment initially operates correctly but later develops intermittent traffic or unexpected failover behavior. The issue may appear after adding equipment, changing the topology, increasing VLANs, modifying routing or LACP, moving cables or ports, or triggering an STP recalculation. It can also occur when no intentional network change has been made.

Symptoms

Typical symptoms include normal traffic processing on the primary FortiGate followed by widespread service loss during failover, failure of a specific segment or interface, or repeated traffic flapping—for example, connectivity works for 10 minutes and then fails for 10 minutes. FortiGate system-event logs may show the affected interface repeatedly changing status.

Environment

FortiGate HA deployments, particularly networks using aggregation or LACP and Spanning Tree Protocol (STP). Relevant topology changes include converting a standalone FortiGate to HA, moving connectivity from core 1 to core 2, adding an intermediate load balancer, proxy, or traffic-management device, increasing VLANs, changing routing, modifying LACP, changing FortiGate or switch cabling and ports, and STP recalculation.

FortiOS version

6.0, 6.2 and above

Root Cause

A common cause is the upstream or downstream switching design, especially STP behavior in an aggregated or LACP topology. STP hold-down and recalculation timers can disable one peer-facing port and later change the active forwarding path. During an intermittent event, the switch may incorrectly forward traffic toward the secondary FortiGate instead of the primary. The secondary unit does not process that traffic. FortiGate only processes frames as received and records interface transitions; it does not initiate the peer-port shutdown. Interface down/up events can also result from a disconnected cable or a port being shut down or disabled on the connected device, with peer-port disablement being the more common HA scenario.

Solution

  1. Identify whether the issue began after a physical or logical network change. Review newly introduced devices, conversion from standalone operation to HA, movement from core 1 to core 2, intermediate load balancers or proxies, VLAN growth, routing changes, LACP changes, cable or port moves, and STP recalculation.

  2. Open the FortiGate system-event logs using the path appropriate for the installed release:

    • FortiOS 6.0: Log & Report -> System Events.
    • FortiOS 6.2 and above: Log & Reports -> Events -> System Events, available in the top-right corner.
  3. Filter the logs for Log Description: Interface status changed.

  4. Locate events for the interface associated with the failed segment or intermittent service. A FortiGate interface-status event is a notification rather than an action taken by the FortiGate. Such events indicate that the appliance detected a physical or peer-induced down/up transition.

  5. Check for the two primary triggers of an interface transition:

    • A cable was disconnected or unplugged from the port.
    • The connected switch or peer device shut down or disabled its port.
  6. Inspect the switch configuration and event history for STP, aggregation, or LACP behavior. Pay particular attention to STP hold-down and recalculation timers because, after the hold-down period expires, STP can refresh or recalculate the forwarding path.

  7. Determine whether the switch is shutting down port1 and then reactivating port2. Verify the corresponding transitions directly on the switch as well as in the FortiGate event logs.

  8. Confirm the intended forwarding path. In an example with the first FortiGate acting as primary and the second acting as secondary, the switch must send traffic toward the first FortiGate. During the intermittent condition, verify that the switch is not forwarding traffic toward the secondary FortiGate, because the secondary will not process it.

  9. If the FortiGate logs align with switch-side port or STP transitions, address the physical and logical network design rather than changing the FortiGate HA configuration. Coordinate the required network integration changes with the network administrator or Fortinet Professional Services.

Verification

After correcting the switch, STP, LACP, cabling, or topology issue, confirm that the switch consistently forwards traffic toward the active primary FortiGate. Perform an HA failover and verify that services, segments, and interfaces remain operational. Recheck Log Description: Interface status changed events to ensure that the affected interface no longer experiences unexplained or periodic down/up transitions.

Tags

No tags yet.

Community rating

/ 5 (0)

Discussion (0)

    No comments yet.