Switching

last person joined: yesterday 

Ask questions and share experiences about EX and QFX portfolios and all switching solutions across your data center, campus, and branch locations.
  • 1.  MAC learning issue

    Posted 04-03-2015 12:54

    Hi all
     
    i just bought a new firewall to replace an old one ( fortigate )
    Firewall was connected to Juniper EX4200 switch but nothing worked
    I searched what could be wrong on fortigate side but all seems to be OK ( my actual firewall is connected on the same switch without any problem )
    On switch side, i saw that when the first firewall port was connected ( only this port connected to the switch ), MAC address was correctly learnt on the switch port ge-0/0/0 but when the second port of the firewall was connected on ge-0/0/1, MAC of firewall port 1 disappeard from the switch and i could only see the MAC of firewall port 2
    are you aware about this kind of problem ?
    Is there any parameter to set up ? ( Sticky MAC already tested without succes )

    I tried on another EX4200 but still the same

    I also tried on a Cisco 3550 switch without any problem

     

    JUNOS Base OS Software Suite [12.3R6.6]

     
    Thanks in advance



  • 2.  RE: MAC learning issue
    Best Answer

     
    Posted 04-03-2015 16:21

    Is there any chance that the Fortinet is running a spanning tree protocol and plugging in the second port causes a loop which the Juniper correctly mitigates by shutting down ge-0/0/0?  You can check interface blocks due to STP by doing a "show ethernet-switching interface" when both ports are plugged in.



  • 3.  RE: MAC learning issue

    Posted 04-04-2015 03:52

    Hi

     

    you found the problem

    i do not understand why this could happen ...

    the firewall is configured in interface mode ( no switch mode ) so it is theorically not possible to find a loop

    i had to disable stp to get my firewall working ( wireshark sniffing did not show any loop )

    I will check with fortinet

     

    Thanks for your help