Always fun when you're doing the same thing as always, and suddenly a new problem appears...
In this case: A Fortigate VM cluster on VMware. There's a dvSwitch portgroup for the HA network with the recommended configuration for such a setup, connected to a dedicated network adapter in either VM.
The Fortigates start talking on their HA network, and after a couple of minutes, both dvSwitch ports go into the blocked state (not at the same time). I have rarely even seen that happening at all? And not with any of the other Fortigate VM clusters we run on our infrastructure?
No idea what's up there, and I have not found any events that shed light on a reason, though ESXi logs do say the dvSwitch port is being blocked. Thanks, that's great?
Looks like some network tracing is in my near future...
#vmware #esxi #dvswitch
(Note: I do know all about the shit that Broadcom is pulling, and if I was in a position to migrate our platform to a different hypervisor, I would. No need to tell me.)