Hi @inSync-MarkValpreda ,
No, it is not expected that the port go error-disable with BPDUGuard. The NGFW does not initiate BPDUs, but it can forward them for L2/VWire interfaces. My guess is that the passive may still have had the default VWire configuration on it when the ports were initially plugged in. The ports connected to the passive NGFW should be configured exactly the same as the corresponding ports connected to the active NGFW. As long as HA is up and the configuration is synced and the NGFW is in passive state, it is safe to bring up the ports to the passive NGFW.
You do not want to setup LACP on ports connected to 2 different NGFWs. With the same config on the ports connected to active and passive, the MAC address should only show on the port connected to the active NGFW. If you want to configure LACP with multiple ports to each NGFW, configure 1 group to 1 NGFW, and a 2nd group to the 2nd NGFW. If you want LACP to be pre-negotiated on the passive NGFW, check the "Enable in HA Passive State" box under the AE interface. This will require that the passive link state be set to auto also.
As you asked, changing the passive link state be set to auto will speed the failover a little bit. The ports will be up on the passive. You should see no traffic or MAC addresses on the passive ports.
Thanks,
Tom
... View more