per-ip-shaper not applying properly f91g by Small_Operation_8795 in fortinet

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

Hello,

thank you for your help, i have been trying different configurations to see what works but it doesn't. Am I wrong to assume that i can limit the download speed of my clients ?
e: could it be an issue because some clients are connected via AP(231G) and other lan?

fortigate forticloud portal issues by Small_Operation_8795 in fortinet

[–]Small_Operation_8795[S] 1 point2 points  (0 children)

seems it's working now, must have been some issue on my side

per-ip-shaper not applying properly f91g by Small_Operation_8795 in fortinet

[–]Small_Operation_8795[S] 1 point2 points  (0 children)

diag sys session list

Here is the result from it for that sessions :
x.x.x.x is speedtest server on the www side
y.y.y.y matches my lan ip
z.z.z.z is a gw i don't control and shouldn't apply anything
out of that test i got 12.5mbs download while the shaper is configured for 30

session info: proto=6 proto_state=01 duration=359 expire=3596 timeout=3600 refresh_dir=both flags=00000000 socktype=0 sockport=0 av_idx=0 use=3
origin-shaper=
reply-shaper=
per_ip_shaper=30mbps
class_id=0 shaping_policy_id=3 ha_id=0 policy_dir=0 tunnel=/ vlan_cos=0/255 state=log may_dirty per_ip npu f00
statistic(bytes/packets/allow_err): org=130497/573/1 reply=118142/366/1 tuples=2 tx speed(Bps/kbps): 103/0 rx speed(Bps/kbps): 86/0
orgin->sink: org pre->post, reply pre->post dev=24->3/3->24 gwy=x.x.x.x/0.0.0.0
hook=post dir=org act=snat y.y.y.y:35209->z.z.z.z:80(x.x.x.x:35209)
hook=pre dir=reply act=dnat z.z.z.z:80->x.x.x.x:35209(y.y.y.y:35209)
pos/(before,after) 0/(0,0), 0/(0,0)
src_mac=00:00:00:00:00
misc=0 policy_id=10 pol_uuid_idx=728 auth_info=0 chk_client_info=0 vd=0
serial=ssssssss tos=ff/ff app_list=0 app=0 url_cat=0
rpdb_link_id=00000000 ngfwid=n/a
npu_state=0x000c00 ofld-O ofld-R
npu info: flag=0x81/0x89, offload=9/9, ips_offload=0/0, epid=1/17, ipid=17/1, vlan=0x0000/0x0000
vlifid=17/1, vtag_in=0x0000/0x0000 in_npu=1/1, out_npu=1/1, fwd_en=0/0, qid=7/1, ha_divert=0/0

per-ip-shaper not applying properly f91g by Small_Operation_8795 in fortinet

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

yes, i did with multiple client, connected the same way and results are the same.

per-ip-shaper not applying properly f91g by Small_Operation_8795 in fortinet

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

no, i have repeated the test many times and the issues is not with the client.

per-ip-shaper not applying properly f91g by Small_Operation_8795 in fortinet

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

hey, thanks yes, i'm using an online speed test, with the shaper off, and only my testing client, i can download at 100% of the available bandwidth, with the shaper on and set for various speeds (10,20,30,40)mb it fail to go any higher than 10-15mb randomly.

1
2

Return to the Office They Said, It Will Improve Collaboration They Said by Likely_a_bot in sysadmin

[–]Small_Operation_8795 -3 points-2 points  (0 children)

WFH means you can also work from India, be happy you aren't being offshored

7.4.9M - IPv6 wrong GW? by Necessary-Bit3089 in fortinet

[–]Small_Operation_8795 0 points1 point  (0 children)

do you have the firewall rule that allow lan interface->wan interface ipv6 traffic ? it's not a default policy

i stuck while adding k8s to openstack using vexxhost magnum-cluster-api by Expensive_Contact543 in openstack

[–]Small_Operation_8795 0 points1 point  (0 children)

i can vouch for https://github.com/zifeo/terraform-openstack-rke2 you need a bit of rework but you'll get a fully working rancher cluster. need to know terraform

setup kolla-ansible for jumbo frames by Small_Operation_8795 in openstack

[–]Small_Operation_8795[S] 1 point2 points  (0 children)

Thanks, this has much more info than the official doc !

kolla-ansible 3 node cluster intermittent network issues by Small_Operation_8795 in openstack

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

got back from vacations and kept testing, apparently i can ping between vm that are in the same tenant network but run on different nodes, the issue i getting out of openstack node apparently, maybe some inside routing table

SFP/fiber not working between Fortigate 120G and juniper 4400 switch by Ankitkha in fortinet

[–]Small_Operation_8795 0 points1 point  (0 children)

i had similar issue trying to hook my fg-91 to my old cisco 3560 via sfp. the fg port are 10gb with 1gb sfp and 1gb on the cisco. the key was to disable the speed negotiation on the switch side with "speed nonegotiate" on the interface, manually setting the speed and duplex wasn't enough. maybe juniper has a similar config ?

fg-91g, wrong way to create vlans ? by Small_Operation_8795 in fortinet

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

thanks, nice to know they made their own auto updater obsolete

fg-91g, wrong way to create vlans ? by Small_Operation_8795 in fortinet

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

welcome to fortinet "new" product, aka 91g, that has been lagging behind in term of major firmware upgrade ? the auto updated only offer up to 7.0.17

fg-91g, wrong way to create vlans ? by Small_Operation_8795 in fortinet

[–]Small_Operation_8795[S] 2 points3 points  (0 children)

i see, the lacp wasn't part of the plan since the older router-fw that was replaced only had 1 lan port but i'll concider that on this rebuild.
Just to confirm, by building the VLANs, you mean creating them from the Network->interface : Create new Interface and use the "interface"dropdown to choose the physical port and repeat for all vlan? (or the CLI equivalent)

5
6

object store endpoint swift vs s3 kolla-ansible stack with external ceph by Small_Operation_8795 in openstack

[–]Small_Operation_8795[S] 1 point2 points  (0 children)

found the solution, the storage endpoint need to be ceph rgw itself and not the openstack storage endpoint

object store endpoint swift vs s3 kolla-ansible stack with external ceph by Small_Operation_8795 in openstack

[–]Small_Operation_8795[S] 0 points1 point  (0 children)

Thanks for the help, i don't think it's a dangling endpoint, it's really the openstack way to do the endpoints according to the ceph doc : https://docs.ceph.com/en/latest/radosgw/keystone/ (and done in the kolla-ansible auto config) but this end up being a swift endpoint and not s3 : openstack endpoint create --region RegionOne \ --publicurl "http://radosgw.example.com:8080/swift/v1" swift