10-02-2024 06:31 AM - edited 10-08-2024 06:19 PM
hi, we have 2x ASR 1001 and created a bridge domain interface 20. Now we need to create port-channel between ASR and fortinet firewall. Can anyone pls help advise whether below config is correct? Thanks in advance.
interface BDI20 |
description xxxxx |
ip address 10.x.x.1 255.255.255.248 |
int po50 |
desc xxxx |
no ip address |
Solved! Go to Solution.
10-02-2024 07:00 AM
Seems to be right to me but you need to test with the Fortinet to be sure. Some devices does not support port-channel mode Active and you may need to adjust. Another config is encapsulation dot1q. Both need to be tested, unless you already have a confirmation from the Fortinet on this.
10-02-2024 07:26 AM
Hello @Herman2018
Your configuration is well-structured for creating a port-channel between the ASR 1001 and the Fortinet firewall. Just ensure that you verify compatibility and configurations on both sides, and perform thorough testing once set up. If you have specific requirements or need to adjust settings based on your network design, feel free to share those for more tailored advice!
Note: Verify that LACP settings on the Fortinet firewall are compatible with your ASR configuration. Sometimes, different vendors may have unique defaults or requirements...
10-02-2024 07:00 AM
Seems to be right to me but you need to test with the Fortinet to be sure. Some devices does not support port-channel mode Active and you may need to adjust. Another config is encapsulation dot1q. Both need to be tested, unless you already have a confirmation from the Fortinet on this.
10-02-2024 07:26 AM
Hello @Herman2018
Your configuration is well-structured for creating a port-channel between the ASR 1001 and the Fortinet firewall. Just ensure that you verify compatibility and configurations on both sides, and perform thorough testing once set up. If you have specific requirements or need to adjust settings based on your network design, feel free to share those for more tailored advice!
Note: Verify that LACP settings on the Fortinet firewall are compatible with your ASR configuration. Sometimes, different vendors may have unique defaults or requirements...
10-02-2024 07:37 AM
Bridge with forti? I dont get what you want here' and why you use PO?
What you need it make bridge between g0/0/1 and g0/0/2 if FW is in l2 mode.
This make traffic enter to FW inspect and then egress from other interface.
MHM
10-02-2024 06:33 PM - edited 10-08-2024 06:19 PM
10-02-2024 11:23 PM
I never try before' but hope it work as you want
Goodluck
MHM
10-02-2024 11:28 PM
Hello @Herman2018
Just a note: ensure the MTU on both sides (ASR and Fortinet) matches. A mismatch in MTU can cause issues, particularly with services like LACP...
10-02-2024 11:43 PM
hello
for what reason are you bringing - surley you would have l3 between the asrs and the fortinets?
10-02-2024 11:53 PM
he need bridge to make HA work
instead of using SW he use bridge between two routers
but the codes he shared I dont think so it correct
but let him check and update us
MHM
10-02-2024 07:51 AM
hello
What are you bridging and why?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide