Skip to main content
KPS
New Member
September 12, 2019
Question

Fortigate - ARP-Issues after Upgrade 5.6.6 to 5.6.9 - Unicast flooded to all switch-ports

  • September 12, 2019
  • 1 reply
  • 17612 views

Hi!

 

I just updated my 200E-Cluster from 5.6.6 to 5.6.9. Now, I have a very strange issue:

 

The unicast-traffic that passes the fortigate is "acting" like broadcast-traffic.

--> The traffic is sent to every switchport

 

If I monitor the traffic on ANY switchport, I see all the unicast-packets, that where routed by the fortigate.

 

If I ping the fortigate from the destination IP, the problem stops instantly.

 

Do you have any idea, what happens there?

For me, the Fortigate seems to "forget" to use the ARP-table for those packets. If I have "incoming" traffic (destination=fortigate), that ARP seems to work fine.

 

The ARP for one test-server:

 

#diagnose ip arp list | grep 10.49.0.48 index=34 ifname=DMZ-HO-Bond 10.49.0.48 00:50:56:89:xx:xx state=00000004 use=369512 confirm=372713 update=368876 ref=4

 

Thank you for your help!

 

KPS

1 reply

kubimike
New Member
September 12, 2019

since you have a cluster are you doing home-runs with wiring ?

KPS
KPSAuthor
New Member
September 12, 2019

kubimike wrote:

since you have a cluster are you doing home-runs with wiring ?

I do not really understand. The cluster is active-passive. Both nodes have one leg in every network.

kubimike
New Member
September 12, 2019

How many switches do you have connected to the fortigate ?