Ok hold on, this is going to be hard to believe and to describe. I have troubleshooted a lot and cannot find out where the problem lies. Suddenly I had this vague problems, of sites not loading, DNS not resolving, etc. Maybe related to upgrading to 7.0.10 or 7.0.11. Maybe not.
What does not work (but had always worked like this - for years):
What does work:
EDIT: Roblox is "the" way of proving/testing above. As described a lot more is not working smoothly, but a refresh of the page will do. Roblox seems to be a lot more "picky" in the coneection stability.
Both "networks" are giving out the same DNS servers.
I have 6 VLANS connected via the lan hardware switch which all work(ed) well for years. Of which 3 have an IP adress on the VLAN interface and 3 are connected in a software switch with a port.
--> this can also be a separate topic because since this week I discovered the Fortigate does not allow me to select a VLAN anymore as a member of a softwareswitch (!), but this used to work and still works. Nothing to find in any release notes...
I cannot find any mentioning of any change in behavior. Also I have no active subscription on this device (81E) and thus cannot call support.
Is there anything I can do to (more) narrow down this issue?
Since this issue appeared right around updating to 7.0.10 or 7.0.11... could this perhaps possibly be a bug? Have you looked at the packet captures?
IMO you either have to move everything over to the new HW switch and/or downgrade to 7.0.10 and see what happens. Might make most sense to try downgrade to 7.0.10. It still doesn't really make sense to me how that would have this effect on things but you never know!
And yes I looked at the packet captures please re-read the thread.......
You are right. It is hard to follow in the forum type with all the "rabbit hole threads".
I do not dare to downgrade as I read in the release notes not all will work then..,
Downgrading a point release really shouldn't cause any grief. See here for more info:
This is a home network? Just downgrade, see how things behave and if you need to just revert back to the other partition.
There are packets missing in the test99 capture then. How did you capture it? On the FortiGate or on the client itself? Can you please capture from the client?
Created on 04-14-2023 12:33 AM Edited on 04-14-2023 05:05 AM
I reverted back to previous fortios (7.0.10). Instantly it all worked again!!!
Although it loaded my previous configuration (but with ssid bridged via "lan" switch).
When I connected to the (old) lan-switch it direcly started roblox (multiple times) and other sites/systems being slow/unstable on another phone and wired PC instantly worked with no problems.
I reverted back to 7.0.11 now since I use sslvpn and had new config (vlans).
But I cannot conclude any other than that there must be a problem with 7.0.11...
What can that be?
From my perspective I may add the keywords "bug", "7.0.11", "existing hardware switch"
Sorry it's not very clear... you went back to 7.0.11 after it worked on 7.0.10? Is it working now on 7.0.11?
Created on 04-14-2023 12:37 PM Edited on 04-14-2023 12:39 PM
I did revert to 7.0.10. Then I went back to 7.0.11 (via your alternate firmware link).
In 7.0.10 it works again. In 7.0.11 it does not.
I reverted back to 7.0.11 after being at 7.0.10 (where everything works) because when I went back to 7.0.10 all my "old" config was loaded. But again, ssid bridged to lan switch is both the same config in 7.0.10 and 7.0.11.
OK so you have an old config that works. I would say its more to do with your config than the firmware upgrade.
What changes to config did you make after going to 7.0.11?
Come on... it's not the config.
It's not the old config that works, its 7.0.10. Since 7.0.11 introduced this issue I started to rebuild my config.
But again, the part with bridging the main ssid directly to lan swith never changed!!
In 7.0.10 that works. In 7.0.11 not.
And that started a few weeks ago directly after upgrading to 7.0.11
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1739 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.