Description | This article describes the issue where some or all Traffic on aggregate interfaces are affected on NP7 platforms. |
Scope | FortiGate NP7 platforms. |
Solution |
In this scenario, a client PC (20.0.0.1) on Vlan 352, sends an ICMP echo to the server (10.0.0.1) on VLAN 354.
Fortigate_1 (V-PROXY-RZ) # di sniffer packet any 'host 10.0.0.1 and icmp' 4 0 l
Analyzing the sniffer, the FortiGate passes the traffic, and debugs show the same, on the switch side when the packets were captured, the reply was seen but the FortiGate does not see the same.
When the issue happens, some traffic may work and some are affected, or all traffic on the aggregates is affected.
To mitigate this problem, changes in the way traffic is handled at the NP level must be made, as a workaround, the commands below. The commands take effect post-reboot, and the device will show a prompt for reboot.
config system npu WARNING: When default-qos-type is set to shaping max-receive-unit should also be set to 6000, and all interface MTUs should be set to 6000 or less. Interface MTU will be lowered automatically.
Note: MTU on all interfaces will be set to 6000 if it is above this number. |