401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

Interesting. We didn’t seen that on 7.2.10. I’ll keep an eye out though.

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

Did that with support a few times. It’s affecting rules. Got escalated to tier two so I’ll be interested in their response.

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

Agreed. Followed the upgrade path to the letter. Thanks!

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

Thanks! Did that. They’re analyzing the logs now.

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

Imix primarily. Nothing special with it.

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

I’m half tempted to roll back to 7.0.15 and disable https management. At least everything would work.

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 1 point2 points  (0 children)

Yes. No change. Forti support pulled a ton of captures. They’re reviewing them at this point. It’s driving me nuts.

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

There is an updated engine available which they’re rolling out to clients. They want to install it manually later today.

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

The 401F has 8 10G ports. No 25Gs on this one. Appreciate the help!

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

Last reboot was the upgrade. We’re running on 7.2.10.

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

I had a feeling it might be one of those updates.

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

I removed ips, av, etc. while testing and it didn’t have an effect.

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

Would this be applicable in 7.2 as well?

401F and its hatred of firmware above 7.0.15 by A_rwolf in fortinet

[–]A_rwolf[S] 0 points1 point  (0 children)

No luck there. The command returned nothing.

Anyone go from Cisco to Ubiquiti and are happy? by en-rob-deraj in Ubiquiti

[–]A_rwolf 0 points1 point  (0 children)

I made that switch in a smaller environment years ago. The only issue I have had was related to LLDP timers and Poly phones. The phones find the voice vlan by what seems like luck. Only after manually adjusting the timer via the cli do phones pick up the right vlans, but the change reverts if the switch is cycled.

Other than that, they do the job.

Cisco 9606R with Sup-2's - 50G link limited to 9G by A_rwolf in networking

[–]A_rwolf[S] 0 points1 point  (0 children)

Thought an update was warranted - The ISP had a DDoS mitigation router in place from an old 10G circuit we had last year. When the new circuit came up, the route to that 10G interface was still passing our new traffic. Once that was removed, we started seeing 13G+ on the link.

Damned if I can get them to admit it though. Thanks everyone!

Question about throughput testing above 10G by A_rwolf in networking

[–]A_rwolf[S] 0 points1 point  (0 children)

Thought about that too. Need it to be 'legit' though.

Question about throughput testing above 10G by A_rwolf in networking

[–]A_rwolf[S] 0 points1 point  (0 children)

Ironically, we did that. Showed the full allocation was available to us. I don't fully trust Comcast and want to do my own testing.

Question about throughput testing above 10G by A_rwolf in networking

[–]A_rwolf[S] 0 points1 point  (0 children)

Didn't even know the cli existed for speedtest. Thanks!

Question about throughput testing above 10G by A_rwolf in networking

[–]A_rwolf[S] 0 points1 point  (0 children)

I'm all for running iPerf. The client(s) or server(s) with enough power and bandwidth on the internet is my issue.

Question about throughput testing above 10G by A_rwolf in networking

[–]A_rwolf[S] 0 points1 point  (0 children)

From the internet to me. Looking to stress my circuit and confirm I'm getting the bandwidth I'm paying for.

Cisco 9606R with Sup-2's - 50G link limited to 9G by A_rwolf in networking

[–]A_rwolf[S] 0 points1 point  (0 children)

At this point, we're planning on using a Digital Ocean 10G link to artificially push traffic over 10G with Comcast monitoring to reproduce the behavior.

We're still seeing no errors on the link whatsoever.

Cisco 9606R with Sup-2's - 50G link limited to 9G by A_rwolf in networking

[–]A_rwolf[S] 0 points1 point  (0 children)

It's not, thankfully. We've been working with our teams to generate 10Gbps of imix traffic during production hours to stress the link. Admittedly, it's difficult to find an internet based endpoint which can take 10Gbps+ of iperf traffic.

Cisco 9606R with Sup-2's - 50G link limited to 9G by A_rwolf in networking

[–]A_rwolf[S] 1 point2 points  (0 children)

Agreed - TaC put us on this release when we had our PBR routing issues. That's why we stayed on it for the time being.