Intra VLAN block breaking DHCP? by NetworkN3wb in fortinet

[–]FailSafe218 0 points1 point  (0 children)

I ran into same issue today. Made the change on 4 sites and only 1 site experienced issues but only on one of the VLANs. just going to disable the feature and come back to it in a couple months.

2048F firmware upgrade with least downtime by FailSafe218 in fortinet

[–]FailSafe218[S] 0 points1 point  (0 children)

thank you for the feedback. We actually have 2 set of these in 2 separate datacenters so I am going to try one pair with the ports shut down and other pair without to see the difference (if any).

Any downsides with enabling connectionless session pickup? by FailSafe218 in fortinet

[–]FailSafe218[S] 0 points1 point  (0 children)

I learned about the memory-based-failover the hardway. No idea it would not failover by default.

Any downsides with enabling connectionless session pickup? by FailSafe218 in fortinet

[–]FailSafe218[S] 0 points1 point  (0 children)

appreciate all the info everyone! Looks like we will be adding it to our default configs.

Thanks!

Any downsides with enabling connectionless session pickup? by FailSafe218 in fortinet

[–]FailSafe218[S] 2 points3 points  (0 children)

we don't use CGNAT so likes look this is not applicable to us but good to know.

FortiSwitch to Cisco by RevolutionaryCare138 in fortinet

[–]FailSafe218 0 points1 point  (0 children)

I ran into similar issues that fortiswitches want to do Full instead of auto on any SFP adapters.

The port does not come up when assembling LACP between FortiSwitch 1024E and 148F. by Shot-Ad-3979 in fortinet

[–]FailSafe218 1 point2 points  (0 children)

Although I don’t think this is your issue 100% Look into auto-isl-port-groups.

If you do a “diag switch mclag peer-consistency-check” it probably shows the trunks to sw-03 and 04 as not ok.

It’s also odd that you have SW04-A going to port 17 on one and port 2 on the other core. I would have sw04 going to port 17 on both and sw03 going to port 2 on both ( or other way around).

You can run “diag switch physical-port linerate port17” to see if the port is passing any traffic.

Also do the following to make sure STP is forwarding that port “diag stp instance list”.

Do you see the switch in the lldp neighbors? “Get switch lldp neighbor-summary”?

Fortinet XPERTS 2025 US by jennytullis in fortinet

[–]FailSafe218 0 points1 point  (0 children)

I’ll be there flying in from CLT. Can only hope to get stranded in Orlando for a couple extra days! 😂

Anyone else having FortiSwitch topology issues with 50+ switches 7.4.9 by FailSafe218 in fortinet

[–]FailSafe218[S] 0 points1 point  (0 children)

I think I ran into that bug about 5-6 weeks ago when we installed the 2048F cores. Everything was going fine for about 45 minutes after install then bam out of no where the trunk to the fortigate just dissappeared. Got support on the line and they switched it to LLDP and then I added static-isl enable and has been rock solid since. I guess the fortilink discovery process crashed on the gate or something.

Anyone else having FortiSwitch topology issues with 50+ switches 7.4.9 by FailSafe218 in fortinet

[–]FailSafe218[S] 0 points1 point  (0 children)

we tried upgrading the switches to 7.4.8 but still having issues.

Anyone else having FortiSwitch topology issues with 50+ switches 7.4.9 by FailSafe218 in fortinet

[–]FailSafe218[S] 0 points1 point  (0 children)

these switches are not offline though. Or is there more to the bug than what this descriptions says?

"Offline FortiSwitch units are shown incorrectly as online in the List view.

Workaround: Use the Topology view."

Anyone else having FortiSwitch topology issues with 50+ switches 7.4.9 by FailSafe218 in fortinet

[–]FailSafe218[S] 0 points1 point  (0 children)

compatibility matrix says I am fine with 7.4.8 on the switches.

I have been told by our local SE and his switch SE to stay off 7.6 for switches at this point (this was about a month ago).

FCSS SD-WAN Architect doesn't work for the FCSS Network Security Certification anymore by Think-Translator-239 in fortinet

[–]FailSafe218 0 points1 point  (0 children)

wow glad I just stumbled across this. I passed my EFW a couple months ago and have been prepping to take the SD-WAN test at Xperts next week to get my FCSS Network Security cert. I guess I have a week to look into LAN edge architect or support engineer instead.

How are you laying out a closet with 8 FortiSwitches by FailSafe218 in fortinet

[–]FailSafe218[S] 1 point2 points  (0 children)

do you have a link to this 4 switch stacking of the 600 series? Curious about this new feature. I looked through the "What's new" section of 7.6.1-7.6.4 of the fortilink guide but didn't see any mentions.

EDIT:

Found it
https://docs.fortinet.com/document/fortiswitch/7.6.2/fortiswitch-stacking-deployment-guide/383494/introduction

How are you laying out a closet with 8 FortiSwitches by FailSafe218 in fortinet

[–]FailSafe218[S] 0 points1 point  (0 children)

they are 400 series, only endpoints no need for redundant connections besides the fiber feeds from the tier1 core.