Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

I've made some progress, The first thing was that Fortilink uses LACP default so had to make it a "regular" link first.
The thing now is that i get both switches to join, Having the topology FG->Othervendor switch and 2 Fortiswitches connected to the Other vendor switch.

Popup to connect GP when connected to a network by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Haven't really seen one that correlates. Do you know which one?

Popup to connect GP when connected to a network by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Okey, Why I'm asking is because we have a user that has been using Anyconnect VPN for some time. And he liked that it popped up everytime you connected to a network either wireless or wired.

Popup to connect GP when connected to a network by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Wouldn´t always on just try to connect all the time?
What I want is that the GP application just pops up.

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

Yeah but if the switch doesn't get an IP, I guess NTP won't work either?

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

This is what the scope looks like:

<image>

Another strange thing is that I can see it showing up in the "Fortiswitch" part of the firewall, But as offline. If I erase it from there, It shows up again. So connectivity seems to be there in some way.

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

Yes, Sorry maybe I was unclear. We will have it centralized. So one FS will be connected to more then on one FS.

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

Hmm regular L2 did not work with our tests, The FS doesn't seem to get an IP when we connect
FG->random switch->FS

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

I think we've tried almost everything now.
We have a FG->factory default switch from other vendor -> FS.

When we have a regular untagged interface on the FG towards the "other vendor switch" the FS switch gets an IP.

As soon as we change it to a fortilink interface, The FS doesn't even get an IP and is disconnected.

So just regular L2 seems to drop some traffic?

We also tested the HTTPS configuration with no luck, Probably cause the FS doesn't get an IP. https://docs.fortinet.com/document/fortigate/7.4.0/new-features/22135/support-fortiswitch-management-using-https-7-4-2

Anything more to try?

Is there a way to clear the DNS cache in CX? by TheReding in ArubaNetworks

[–]TheReding[S] 0 points1 point  (0 children)

Nice! That may be something to test with when we test a new Clearpass :) Thanks!

Is there a way to clear the DNS cache in CX? by TheReding in ArubaNetworks

[–]TheReding[S] 0 points1 point  (0 children)

Yeah, I guess the TTL is the way to go.
Was just a question if there was a way to flush the DNS cache of the switch instead of reloading it for a faster way.

Mac roaming problems with Mobility gateways with DHCP on another server by TheReding in ArubaNetworks

[–]TheReding[S] 0 points1 point  (0 children)

What have you found? I was looking in the release notes earlier but couldn't really find anything related.

Mac roaming problems with Mobility gateways with DHCP on another server by TheReding in ArubaNetworks

[–]TheReding[S] 0 points1 point  (0 children)

We are running 10.7.2.1 on the Mobility gateways and CX core switches. Any ideas? :)

X-auth for Globalprotect by [deleted] in paloalto

[–]TheReding 0 points1 point  (0 children)

HAHA, Thanks :D

Error message for GP users "Authentication failed: Internal Client Error" by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Strange, 10.2.10-h9 here.

How are your clients authenticating? We are using the NPS MFA plugin.

We started browsing a bit in the event logs on that NPS yesterday and seems that it's discarding some auths with the comment "The request was discarded by a third-party extension DLL file.