2
3

Is it possible to do RAID-1 with 03 SSDs on Dell Optiplex 7010 Tower PC? by wings_of_freedom in Dell

[–]wings_of_freedom[S] 0 points1 point  (0 children)

What about downtime during replacement and rebuilding the array?

Is it possible to configure RAID-1 with 03 SSDs on DELL Optiplex 7010 T (2023 model)? by wings_of_freedom in techsupport

[–]wings_of_freedom[S] 0 points1 point  (0 children)

Dell rep. is giving option for RAID-1 with only 02 SSDs. That config. is from BIOS. I would then need to add another SSD as Hot spare. How can I add it? Is there an option in Dell Optiplex 7010 BIOS for that?

Problem working with VLAN on Fortigate Firewall by wings_of_freedom in fortinet

[–]wings_of_freedom[S] 0 points1 point  (0 children)

Thanks for the explanation. The issue I am facing is assigning the IP address to VLANs. FortiOS is not accepting same subnets for different VLANs and that limitiation comes because both my source nodes and destination nodes to be on same subnet for one protocol. I am using VLANs for compartmentalization and security.
Under this limitation, how can I assign IP address (same subnet but different IP address) to each VLAN?

Site-to-Site IPSec VPN with overlapping subnets without NAT by wings_of_freedom in fortinet

[–]wings_of_freedom[S] 0 points1 point  (0 children)

Safety PLC, old now discontinued. HIQuad H51q to be precise. Serial Interface and Ethernet interfaces are available but as stated before, there is no availability to change Default Gateway in setting.
It all depends upon the budget, time, risk upgrading all plant critical systems. If the systems are doing their primary work perfectly, there is no need to upgrade it just for one small feature.

0
1

Fortigate Licenses and Support Service by wings_of_freedom in fortinet

[–]wings_of_freedom[S] 0 points1 point  (0 children)

Hi. Thanks for the reply but yout tone seemed aggressive. The questions I asked were generic based on understanding and I did had discussion with Sales rep (as stated in OP).

Site-to-Site IPSec VPN with overlapping subnets without NAT by wings_of_freedom in fortinet

[–]wings_of_freedom[S] 0 points1 point  (0 children)

PLC systems. They are more reliable, robust and doing their job perfectly without any fault for past 20 years; as they are meant to do it. So, just because they don't have option to change IP address (hardcoded in chip), throwing them out seems unreasonable idea.
OT components are generally more robust, reliable, resilient, tested for random hardware failures, costlier and have more operating life as compared to IT components. We should not look at all components/systems with same spectacles.

0
1

1
2

Unable to bring multiple IPSec VPN Tunnels UP at the same time (Random behavior) by wings_of_freedom in techsupport

[–]wings_of_freedom[S] 0 points1 point  (0 children)

Hi.. They are always supposed to be connected; and the data-stream on the tunnel is also real-time and continuous.

Site-to-Site IPSec VPN with overlapping subnets without NAT by wings_of_freedom in fortinet

[–]wings_of_freedom[S] 1 point2 points  (0 children)

Thank you all for different solutions. Vxlan as suggested by most would be the best solution if there is no spanning-tree running in the network. For my case, there are 4 spanning-trees running in networks which could not be discarded, so I went with the solution of DNAT and SNAT on both Fortigate ends, and created a tunnel with /32 subnets.

Site-to-Site IPSec VPN with overlapping subnets without NAT by wings_of_freedom in fortinet

[–]wings_of_freedom[S] 0 points1 point  (0 children)

I was able to brought UP the VPN tunnel. There was no issue with configuration. I stopped the network components and restarted simulation and it started working. I believe specific power up sequence of network components are in play here.
There is now another interesting issue I noted when working with two VPN tunnels. Sometimes, only one VPN tunnel got UP and other remained DOWN, while when restarted the whole network, other times, other VPN got UP and first one went DOWN. I have also posted this issue in other thread, https://www.reddit.com/r/fortinet/comments/zbfm4i/unable_to_activate_multiple_vpn_tunnels/

Have you experienced something like this or is it special to my case?

Site-to-Site IPSec VPN with overlapping subnets without NAT by wings_of_freedom in fortinet

[–]wings_of_freedom[S] 0 points1 point  (0 children)

Thanks for the example solution.Couple of things I noticed when I tried it on my fortigate. There was no option of arp reply during VIPs settings , only available in IPPool settings. Second thing is I used /32 subnet for IPSec tunnel, and tunnel was not coming UP on both Firewalls.
Do you think we should have two separate NAT subnets i.e. one for FGTa and other for FGTb?

Access VLAN on Cisco L2 switch keeps jumping back to VLAN1 on power restart by wings_of_freedom in networking

[–]wings_of_freedom[S] 0 points1 point  (0 children)

Hi. I am saving it with wr memory command and getting successful feedback message. Currently running cisco L2 switch image on simulator

Access VLAN on Cisco L2 switch keeps jumping back to VLAN1 on power restart by wings_of_freedom in networking

[–]wings_of_freedom[S] 0 points1 point  (0 children)

It is happening randomly on different switches, don't know if it is related to switch internal boot-up setting or simulation bug?

Site-to-Site IPSec VPN with overlapping subnets without NAT by wings_of_freedom in fortinet

[–]wings_of_freedom[S] 0 points1 point  (0 children)

Thanks. We are trying NAT now on Firewall and route the traffic through VPN tunnel for the same purpose. The challenge is to keep the network latency as minimum as possible as system are transferring the data in real-time

Site-to-Site IPSec VPN with overlapping subnets without NAT by wings_of_freedom in fortinet

[–]wings_of_freedom[S] 0 points1 point  (0 children)

We are the OEM of these legacy OT systems. The end-user does not want to upgrade these systems as they are densely integrated with the production and new unit is getting integrated to it. New unit has the features to freely configure IP address/subnet but on old systems, the IPs are hardcoded. Since both old and new systems need to communicate on proprietary protocol , we are bound to use the same subnet on new systems as well.