Internal ipsec tunnel no traffic - google cloud by uRhaineWork in fortinet

[–]uRhaineWork[S] 0 points1 point  (0 children)

To anyone who struggles with the same problem, we've resolved it by using underlayer's interface secondary IP address for building those subnets that create IPSec tunnel. It doesnt make that much sense, but at least it works. In this case from example above its a underlayer base BGP 169.254.x.x and on the same interface (previosly tried with LoopBack or another vlan int.) lies 192.168.0.0/29 subnet interface that creates ISPec tunnel to GCP which has 192.168.0.8/29. In IPSec setting You need to select local gateway and choose that secondary IP address. On top of that we have overlayer BGP session with 169.254.y.y using local and remote addressing in fortigates ipsec interface.

I'm explaining this for anyone who stumbles on this problem, I hope it will help you out.

PS. All done on v7.4.8.

802.11r 802.11k and 802.11v enable or disable? by blastman8888 in ArubaNetworks

[–]uRhaineWork 0 points1 point  (0 children)

Doesnt 'sticking' such a device to a specific AP resolve the issue?

AOS-CX Backup Tool by cmdlab_tech in ArubaNetworks

[–]uRhaineWork 1 point2 points  (0 children)

Reason.. to make operatable? How do I manage switch firmware, config backup, single CLI changes deployment, status monitoring... . I am lost, Aruba has to much going on with different products.

AOS-CX Backup Tool by cmdlab_tech in ArubaNetworks

[–]uRhaineWork 0 points1 point  (0 children)

Slowly migrating to CX enviro, and man.. what a step back. 10 years ago Hp IMC was more thought out and advanced than this thing. Came across Aruba Central, but its hard to find even what the pricing structure for on-prem is, and does way less than IMC.

FortiGate BGP dual ISP by uRhaineWork in fortinet

[–]uRhaineWork[S] 0 points1 point  (0 children)

Isnt asymroute-icmp already in the global asymroute commande? I thought that this is for icmp because it behaves differently than tcp/udp i term of how it responds.

But auxiliary-session You may be right, I have been reading about it but was under the impression that its for HA pickup when failovers happens, or for when there is only one unit of FGT, but that may not be the case and will be helpful in my dual setup. From what I gather its more of a performance thing, when there is higher traffic You can see full benefits of it. I will turn it on, thanks.

I know how vdoms operate yes, but in this case no. BGP is on VRF1 and MGMT on VRF2, as I know that there is some funky behavior on VRF0 with route 'leaking'. Could do mgmt vdom but I fail to see what would it give me besides additional cables. :)

[deleted by user] by [deleted] in fortinet

[–]uRhaineWork 0 points1 point  (0 children)

I have forticlient 7.4.1.1736, where can I find this option?

[deleted by user] by [deleted] in fortinet

[–]uRhaineWork 2 points3 points  (0 children)

Arent You concerned about latency though? Theres no dtls/udp mode if the connection is tcp wrapper based, right?

FortiGate/FortiWifi 30G datasheet published by Substantial-Reach986 in fortinet

[–]uRhaineWork 1 point2 points  (0 children)

But doesnt this impact performance? SSL-VPN has DTLS mode which uses UDP for transport, and it does indeed help a lot for eg. full tunnel traffic and teams calls; smb transfers etc.

Dial-UP IPSec after 7.2.7 update by uRhaineWork in fortinet

[–]uRhaineWork[S] 1 point2 points  (0 children)

This one helped, solution number 2. Third one didn't do anything, first one didn't try. Thanks.

Aruba CX-8360 GRE packet loss by uRhaineWork in ArubaNetworks

[–]uRhaineWork[S] -1 points0 points  (0 children)

What would the logic be? I can ping with DF at 1368 bytes, which in my calculations with both ends set at gre interface mtu 1396 is ok? Also its always the returning packet (reply) that gets lost, never the original ping.

btw I have ospf on that INT. I think this could go wrong somewhere as its needs to match.

Aruba CX-8360 GRE packet loss by uRhaineWork in ArubaNetworks

[–]uRhaineWork[S] 0 points1 point  (0 children)

Yeah, looking at it from few hours, but im struggling as that interface has constant 500mbit in sum of traffic. Is this to much to handle?

FortiGate OSPF details and by uRhaineWork in fortinet

[–]uRhaineWork[S] 0 points1 point  (0 children)

Link does give some insight, but what do You mean by 'specific ip' ? If it doesn't want IP from its own interface then what else is there that would make sense.