In FortiOS v7.4.12 and v7.6.5, CAPWAP encapsulated small fragments may be dropped by the NP chip.
Running the following command multiple times shows that the counter udp_ulite_minlen is increasing.
diagnose npu np7 dce-drop-all
[NP7_0]
Counter EIF_0 EIF_1 EIF_2 EIF_3 EIF_4 EIF_5 EIF_6 EIF_7 Total
------------------------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ------------
[27]tcp_csum 229 220 212 209 176 208 207 185 1646
[29]tcp_synoptpar 243 236 252 252 186 224 226 205 1824
[31]udp_ulite_minlen 14564938 14559284 14560158 14564480 14215132 14216066 14209976 14211117 115101151
[32]udp_csum 81 76 66 73 42 67 52 50 507
[38]icmp_csum 529 530 545 543 440 438 504 467 3996
------------------------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ------------
How to fix:Â
One temporary fix is to run the CLI commands below on the CLI of the FortiGate. These commands will not survive a reboot and will need to be re-issued.
To reverse the setting, modify the last digit from 0 to 1 or 1 to 0, depending on whichvalue was set before.
NP7lite platform:
diagnose npu np7lite setreg 0 eif.ihp.ihp_wrap.ihp_chk.l4aps_ena.cwp_fflag_ena 1
diagnose npu np7lite setreg 0 eif.ihp.ihp_wrap.ihp_chk.l4chk_act.udp_ulite_minlen_err_act 0
diagnose npu np7lite setreg 0 eif.ihp.ihp_wrap.ihp_chk.l4chk_act.capwap_minlen_err_act 0
NP7 platform:
diagnose npu np7 setreg "0~1" eif.eif_"0~7".ihp.ihp_wrap.ihp_chk.l4aps_ena.cwp_fflag_ena 1
diagnose npu np7 setreg "0~1" eif.eif_"0~7".ihp.ihp_wrap.ihp_chk.l4chk_act.udp_ulite_minlen_err_act 0
diagnose npu np7 setreg "0~1" eif.eif_"0~7".ihp.ihp_wrap.ihp_chk.l4chk_act.capwap_minlen_err_act 0
Or:
diagnose npu np7lite setreg 0 eif.ihp.ihp_wrap.ihp_parser1.l4tun_ctrl.cwp_minlen 17
diagnose npu np7 setreg "0~1" eif.eif_"0~7".ihp.ihp_wrap.ihp_parser1.l4tun_ctrl.cwp_minlen 17
A fix is scheduled for FortiOS v7.4.13 and v7.6.8.
|