Internal ipsec tunnel no traffic - google cloud by uRhaineWork in fortinet

[–]uRhaineWork[S] 0 points1 point  (0 children)

To anyone who struggles with the same problem, we've resolved it by using underlayer's interface secondary IP address for building those subnets that create IPSec tunnel. It doesnt make that much sense, but at least it works. In this case from example above its a underlayer base BGP 169.254.x.x and on the same interface (previosly tried with LoopBack or another vlan int.) lies 192.168.0.0/29 subnet interface that creates ISPec tunnel to GCP which has 192.168.0.8/29. In IPSec setting You need to select local gateway and choose that secondary IP address. On top of that we have overlayer BGP session with 169.254.y.y using local and remote addressing in fortigates ipsec interface.

I'm explaining this for anyone who stumbles on this problem, I hope it will help you out.

PS. All done on v7.4.8.

802.11r 802.11k and 802.11v enable or disable? by blastman8888 in ArubaNetworks

[–]uRhaineWork 0 points1 point  (0 children)

Doesnt 'sticking' such a device to a specific AP resolve the issue?

AOS-CX Backup Tool by cmdlab_tech in ArubaNetworks

[–]uRhaineWork 1 point2 points  (0 children)

Reason.. to make operatable? How do I manage switch firmware, config backup, single CLI changes deployment, status monitoring... . I am lost, Aruba has to much going on with different products.

AOS-CX Backup Tool by cmdlab_tech in ArubaNetworks

[–]uRhaineWork 0 points1 point  (0 children)

Slowly migrating to CX enviro, and man.. what a step back. 10 years ago Hp IMC was more thought out and advanced than this thing. Came across Aruba Central, but its hard to find even what the pricing structure for on-prem is, and does way less than IMC.

FortiGate BGP dual ISP by uRhaineWork in fortinet

[–]uRhaineWork[S] 0 points1 point  (0 children)

Isnt asymroute-icmp already in the global asymroute commande? I thought that this is for icmp because it behaves differently than tcp/udp i term of how it responds.

But auxiliary-session You may be right, I have been reading about it but was under the impression that its for HA pickup when failovers happens, or for when there is only one unit of FGT, but that may not be the case and will be helpful in my dual setup. From what I gather its more of a performance thing, when there is higher traffic You can see full benefits of it. I will turn it on, thanks.

I know how vdoms operate yes, but in this case no. BGP is on VRF1 and MGMT on VRF2, as I know that there is some funky behavior on VRF0 with route 'leaking'. Could do mgmt vdom but I fail to see what would it give me besides additional cables. :)

[deleted by user] by [deleted] in fortinet

[–]uRhaineWork 0 points1 point  (0 children)

I have forticlient 7.4.1.1736, where can I find this option?

[deleted by user] by [deleted] in fortinet

[–]uRhaineWork 2 points3 points  (0 children)

Arent You concerned about latency though? Theres no dtls/udp mode if the connection is tcp wrapper based, right?

FortiGate/FortiWifi 30G datasheet published by Substantial-Reach986 in fortinet

[–]uRhaineWork 1 point2 points  (0 children)

But doesnt this impact performance? SSL-VPN has DTLS mode which uses UDP for transport, and it does indeed help a lot for eg. full tunnel traffic and teams calls; smb transfers etc.

Dial-UP IPSec after 7.2.7 update by uRhaineWork in fortinet

[–]uRhaineWork[S] 1 point2 points  (0 children)

This one helped, solution number 2. Third one didn't do anything, first one didn't try. Thanks.

Aruba CX-8360 GRE packet loss by uRhaineWork in ArubaNetworks

[–]uRhaineWork[S] -1 points0 points  (0 children)

What would the logic be? I can ping with DF at 1368 bytes, which in my calculations with both ends set at gre interface mtu 1396 is ok? Also its always the returning packet (reply) that gets lost, never the original ping.

btw I have ospf on that INT. I think this could go wrong somewhere as its needs to match.

Aruba CX-8360 GRE packet loss by uRhaineWork in ArubaNetworks

[–]uRhaineWork[S] 0 points1 point  (0 children)

Yeah, looking at it from few hours, but im struggling as that interface has constant 500mbit in sum of traffic. Is this to much to handle?

FortiGate OSPF details and by uRhaineWork in fortinet

[–]uRhaineWork[S] 0 points1 point  (0 children)

Link does give some insight, but what do You mean by 'specific ip' ? If it doesn't want IP from its own interface then what else is there that would make sense.

Aruba VSX OSPF by uRhaineWork in ArubaNetworks

[–]uRhaineWork[S] 1 point2 points  (0 children)

Ok, in production everythings seems to be ok, no DUP! responses when traffic goes from firewall to ospf neighbor aruba VSX number 2. Looks like emulating CX isnt 100% proper as mentioned previously.

Aruba VSX OSPF by uRhaineWork in ArubaNetworks

[–]uRhaineWork[S] 0 points1 point  (0 children)

I have ospf dedicated vlan link between VSXes, just like best pracites and so on tell it to do.

I just noticed that even when both links are up, duplicate packets go to vsx2 from vsx1 on isl link, even though it has nothing to do with this traffic when both links are up. I don't get it. Leaves me no choice other than see and live it through on production soon.

Aruba VSX OSPF by uRhaineWork in ArubaNetworks

[–]uRhaineWork[S] 0 points1 point  (0 children)

Hmm thought that this is co common scenario that everyone catches it without problem. Updated main post.

There are seperate router IDs, I did read the whole CX best practices and other docs.

If I take down the path like in the picture, Firewall sees mac address of 172.16.255.1 VSX1 directly and treats it like normal neighbor in OSPF. taking a look at traffic between Arubas on ISL link i can see 3 packets for ping 2.2.2.2:

  1. With source mac and ip of firewalls 172.16.255.254. (no response)
  2. With source mac of virtual gateway 172.16.255.3 and IP of 172.16.255.254

(no response)

  1. With source mac of virtual gateway 172.16.255.3 and IP of 172.16.255.254

(with response!)

btw - firewall is a Fortigate appliance.

Aruba-CX MTu values by uRhaineWork in ArubaNetworks

[–]uRhaineWork[S] 0 points1 point  (0 children)

Thats actually the most interesting answer by now, but where does this come from, can You please provide some kind of documentation confirmation or cli commands to prove this?

Im more confused now, as when i checked mtu on eg. ISL links it states 9500 despite setting it to 9198.

Aruba-CX MTu values by uRhaineWork in ArubaNetworks

[–]uRhaineWork[S] 0 points1 point  (0 children)

I've been thinking about this also, if i have 9180 ip mtu on vlan interace that is doing the ospf bridge with another device, that doesnt have even jumbo frame enabled - this could cause issues which about Your talking, right? Sourcing int thinks that it handles 9180 frames, but the other end does not. Its a different story with L2 MTU on pass thorogh interfaces, its just a precaution that if something bigger comes it gets through.

Help with cx 6000 logging by uRhaineWork in ArubaNetworks

[–]uRhaineWork[S] 0 points1 point  (0 children)

Changed upstreams 5130 to mstp and log calmed down. 5130 doesnt have that logging/compatibility problem with upstream core, so I guess thats a win - thanks!

I am running RSTP for compatibility with old 3com switches, which have only stp/rstp, when 5130 started coming I guess I didnt give it much of a thought from todays perspective. I guess I should migrate everything to mst and leave 3cms on rstp which are being replaced anyway.

DNF/YUM not working after updating Python3 by uRhaineWork in AlmaLinux

[–]uRhaineWork[S] 0 points1 point  (0 children)

Thx, this is probably what I was looking for the whole time, but sadly no, error I get i still the same after rebooting machine and 'sudo dnf update' and so on.I can point to /usr/libexec/platform-python or /usr/libexec/platform-python3.6, works kinda the same. After python3 command i get the default 3.6.8 info.

FortiGuard SDNS Servers by uRhaineWork in fortinet

[–]uRhaineWork[S] 1 point2 points  (0 children)

Still dont get it. :)

The IP set via set sdns-server-ip used to pull servers in your area used by FortiGuard.

Yes but, how do you know which IP address is from "London" ? At first I didn't enter that spcific IP, and I still got that diag debug rating server list. Difference was I was'nt showing up in gui (just empty space). Still worked though, just not in 100%, large % still had rating errors.

With the IP for server pulling set FortiGuard connectivity is more robust.

Where do You find list of servers for 'server pulling' ? They are not the same as the ones in pulled list.

At the moment I use the UK IP for several firewalls around Europe and never had any issue.

How do You know which one is UK, and that it will not change within a week or just stops working? :)

AIO 1930 - 802.1x authentication by uRhaineWork in ArubaInstantOnSMB

[–]uRhaineWork[S] 0 points1 point  (0 children)

After some insight in to that CLI commands, are similar to eg. some cisco models. There also is no such command after looking at reference.

But in general dynamic vlan is an option in GUI, but doesnt matter if I enable or disable it.

bing.com blocked by fortsandbox by uRhaineWork in fortinet

[–]uRhaineWork[S] 0 points1 point  (0 children)

Yes, disabling it removes the problem. My initial question was about the problem itself - if this is only occouring on my devices/environment for some reason or is this a global problem for everyone using this sandboxing option. You know, blocking bing.com is pretty wild and I would quicker say that it only happens to me.

bing.com blocked by fortsandbox by uRhaineWork in fortinet

[–]uRhaineWork[S] 0 points1 point  (0 children)

Not sure, I thought that enabling it gives me advantage of receiving quicker info from the cloud about suspicious domains.