<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: FortiGate/Cisco Layer 2 woes</title>
	<atom:link href="http://www.108.bz/posts/it/fortigate-cisco-layer-2-woes/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.108.bz/posts/it/fortigate-cisco-layer-2-woes/</link>
	<description>Wandering futilities...</description>
	<lastBuildDate>Fri, 20 Jan 2012 13:06:19 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.1</generator>
	<item>
		<title>By: Giuliano</title>
		<link>http://www.108.bz/posts/it/fortigate-cisco-layer-2-woes/comment-page-1/#comment-4129</link>
		<dc:creator>Giuliano</dc:creator>
		<pubDate>Wed, 06 Apr 2011 09:30:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.108.bz/?p=103#comment-4129</guid>
		<description>Thank you Dan for yet another update. Never experienced such a behaviour though. The issues I had have always been solved by turning off auto negotiation.
As for Fortigate TAC, I share your feelings. It&#039;s a pity because the boxes themselves are quite nice (compared to other UTM devices in the same market/price segment).

ciao,
--
Giuliano</description>
		<content:encoded><![CDATA[<p>Thank you Dan for yet another update. Never experienced such a behaviour though. The issues I had have always been solved by turning off auto negotiation.<br />
As for Fortigate TAC, I share your feelings. It&#8217;s a pity because the boxes themselves are quite nice (compared to other UTM devices in the same market/price segment).</p>
<p>ciao,<br />
&#8211;<br />
Giuliano</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://www.108.bz/posts/it/fortigate-cisco-layer-2-woes/comment-page-1/#comment-4048</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Thu, 31 Mar 2011 06:31:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.108.bz/?p=103#comment-4048</guid>
		<description>Hi Giuliano,

Thanks for replying, I lost this link and couldn&#039;t find it, but I somehow found this again from google today.
The problem I am having is kind of solved... The problem is caused by both FortiGate 60Bs and the Cisco/Linisys switches that we are using. The Cisco/Linksys (SRW224G4P) switch have a weird bug that will sometimes lock up and as soon as it locks up, all the ports on the switch will stop working and you can&#039;t ping or remote access the switch at all! Recently I found that this might be caused by mismatch of duplex setting between the switch and the device connecting to it (PS. I am already using latest version of firmeware - v1.3.1 for the switch). The problem on the FortiGate is that it just won&#039;t able to connect to the switch with 100full, the switch would connect to FortiGate with 100half and FortiGate would connect to the switch with 100full. After a while of running, the switch would lock up. This happened to Cisco 1800 router as well. The setting on the router is 100full and switch is running with 100half, when this happens, the switch will lock up at least twice a day!
One last thing, if you have a chance, try run the following two commands on the FortiGate:

Global mode:
diagnose hardware deviceinfo nic dmz

Vdom mode:
get system interface physical


I get different duplex results from these 2 commands!! One says half duplex and another says full duplex!!

To be honest, I had so many of these type of bugs with FortiGate, I am really getting sick and tired of them... And not to mention the speed and ability of their TAC support, it&#039;s slow and unhelpful most of the time.

So my solution is to set the connection between the FortiGate and Cisco/Linksys switch to 100half, that seems to fix the problem.


Cheers,
Dan</description>
		<content:encoded><![CDATA[<p>Hi Giuliano,</p>
<p>Thanks for replying, I lost this link and couldn&#8217;t find it, but I somehow found this again from google today.<br />
The problem I am having is kind of solved&#8230; The problem is caused by both FortiGate 60Bs and the Cisco/Linisys switches that we are using. The Cisco/Linksys (SRW224G4P) switch have a weird bug that will sometimes lock up and as soon as it locks up, all the ports on the switch will stop working and you can&#8217;t ping or remote access the switch at all! Recently I found that this might be caused by mismatch of duplex setting between the switch and the device connecting to it (PS. I am already using latest version of firmeware &#8211; v1.3.1 for the switch). The problem on the FortiGate is that it just won&#8217;t able to connect to the switch with 100full, the switch would connect to FortiGate with 100half and FortiGate would connect to the switch with 100full. After a while of running, the switch would lock up. This happened to Cisco 1800 router as well. The setting on the router is 100full and switch is running with 100half, when this happens, the switch will lock up at least twice a day!<br />
One last thing, if you have a chance, try run the following two commands on the FortiGate:</p>
<p>Global mode:<br />
diagnose hardware deviceinfo nic dmz</p>
<p>Vdom mode:<br />
get system interface physical</p>
<p>I get different duplex results from these 2 commands!! One says half duplex and another says full duplex!!</p>
<p>To be honest, I had so many of these type of bugs with FortiGate, I am really getting sick and tired of them&#8230; And not to mention the speed and ability of their TAC support, it&#8217;s slow and unhelpful most of the time.</p>
<p>So my solution is to set the connection between the FortiGate and Cisco/Linksys switch to 100half, that seems to fix the problem.</p>
<p>Cheers,<br />
Dan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giuliano</title>
		<link>http://www.108.bz/posts/it/fortigate-cisco-layer-2-woes/comment-page-1/#comment-2400</link>
		<dc:creator>Giuliano</dc:creator>
		<pubDate>Fri, 03 Dec 2010 09:03:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.108.bz/?p=103#comment-2400</guid>
		<description>Dear Dan,

  I had the issue while router and firewall were directly attached via a crossover cable. I&#039;m pretty sure that using fixed speed/duplex on both devices would&#039;ve solved it but I had no access to the router. Did you do that? I&#039;d follow these steps:
- Turn off auto-negotiation and use fixed (say) 100Mbps/Full Duplex. On each of the router&#039;s ethernet ports. On each of the firewall&#039;s ethernet ports. If there are switches in between, on the switches&#039; ports where firewall/router are connected.
- Make sure that the issue really lies on the firewall facing side of the router by pinging the router&#039;s WAN interface from outside of the Company.
- Disconnect a firewall from a router and put a switch between them (or, if there already was one, use a different brand of switch). See if that makes lock-ups go away.

  I&#039;d be glad if you&#039;ll keep me posted about the issue. I noticed that FortiGate auto-negotiation doesn&#039;t play well with ProCurve switches, also (serious performance issues, but no lock-ups). But in any of the cases I faced, turning auto-negotiation off has been enough.

ciao,
--
Giuliano</description>
		<content:encoded><![CDATA[<p>Dear Dan,</p>
<p>  I had the issue while router and firewall were directly attached via a crossover cable. I&#8217;m pretty sure that using fixed speed/duplex on both devices would&#8217;ve solved it but I had no access to the router. Did you do that? I&#8217;d follow these steps:<br />
- Turn off auto-negotiation and use fixed (say) 100Mbps/Full Duplex. On each of the router&#8217;s ethernet ports. On each of the firewall&#8217;s ethernet ports. If there are switches in between, on the switches&#8217; ports where firewall/router are connected.<br />
- Make sure that the issue really lies on the firewall facing side of the router by pinging the router&#8217;s WAN interface from outside of the Company.<br />
- Disconnect a firewall from a router and put a switch between them (or, if there already was one, use a different brand of switch). See if that makes lock-ups go away.</p>
<p>  I&#8217;d be glad if you&#8217;ll keep me posted about the issue. I noticed that FortiGate auto-negotiation doesn&#8217;t play well with ProCurve switches, also (serious performance issues, but no lock-ups). But in any of the cases I faced, turning auto-negotiation off has been enough.</p>
<p>ciao,<br />
&#8211;<br />
Giuliano</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Huang</title>
		<link>http://www.108.bz/posts/it/fortigate-cisco-layer-2-woes/comment-page-1/#comment-2399</link>
		<dc:creator>Dan Huang</dc:creator>
		<pubDate>Fri, 03 Dec 2010 08:09:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.108.bz/?p=103#comment-2399</guid>
		<description>I believe we are having the same problem here...
We got about 90 FortiGate 60 firewalls and many Cisco &amp; Cisco/Linksys switches, once awhile the link between the FG firewall and Cisco switch would lock up, and the only fix it to restart the Cisco router. This is causing me a serious headache as I am the only network administrator that look after network devices.
I tried changing to different speed and duplex when the switch port is locked up but it doesn&#039;t help at all. Also when it is locked up, I turned on the sniffer on the FortiGate firewall, it can&#039;t &#039;see&#039; anthing as if nothing is on the other end...

I just can&#039;t believe I have to deal with these type of problem and it seems like a basic network 101 but can&#039;t be solved...

Please do let me know if you have any further information. Much appriciated!


Cheers,
Dan</description>
		<content:encoded><![CDATA[<p>I believe we are having the same problem here&#8230;<br />
We got about 90 FortiGate 60 firewalls and many Cisco &amp; Cisco/Linksys switches, once awhile the link between the FG firewall and Cisco switch would lock up, and the only fix it to restart the Cisco router. This is causing me a serious headache as I am the only network administrator that look after network devices.<br />
I tried changing to different speed and duplex when the switch port is locked up but it doesn&#8217;t help at all. Also when it is locked up, I turned on the sniffer on the FortiGate firewall, it can&#8217;t &#8216;see&#8217; anthing as if nothing is on the other end&#8230;</p>
<p>I just can&#8217;t believe I have to deal with these type of problem and it seems like a basic network 101 but can&#8217;t be solved&#8230;</p>
<p>Please do let me know if you have any further information. Much appriciated!</p>
<p>Cheers,<br />
Dan</p>
]]></content:encoded>
	</item>
</channel>
</rss>

