Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jlozen
New Contributor

PPPOE and 60D

I'm currently having issues getting a 60D running firmware 5.2 to connect to the internet through a modem in bridged mode. I've successfully done this many times in the past using different ISPs. I've tried everything I know and still can't get the connection to come up. My current setup is a Netgear DM111PSP with a single cable running to the WAN1 interface on the 60D.

 

I have confirmed that the PPPOE credentials are valid. I did a factory reset on the modem and reentered the credentials and got internet connectivity to the whole network with the modem in modem+router mode. When putting it in bridged mode and having the FortiGate 60D do the authentication I have had no success.

 

I've reentered the PPPOE credentials on the 60D a number of times using both the web interface GUI as well as the CLI and am sure they're entered properly. I tried using 'diag debug enable' 'diag debug application ppp 255' and the only output I get is PPPd has started and PPPd has exited.

 

Has anyone else experienced any similar issues or have any more troubleshooting ideas to get this ironed out?

4 REPLIES 4
ede_pfau
SuperUser
SuperUser

hi,

 

I happen to have had the exact same hardware and line in the past, running v4.3 IIRC. First off, the 111 isn't exactly what I'd call a reliable modem. It gets hot and tends to work spuriously. So my first advice would be to get a second modem. I've had good results with a D-Link DSL-321B which is for ADSL2/2+ on Annex B (ISDN) lines. But frankly, any ADSL modem would do. With AVM FritzBox I've seen malfunctions after a while - steady as a rock while being a router, but unreliable as a modem.

 

Next, I don't think the configuration on the FGT is wrong. It more sounds like the connection is bad (if the hardware doesn't apply, see above). That could be the cable, the need for cross-over TP cabling, a mismatch in interface speed (the 111 is Fast Ethernet only) or duplex mode. That's why trying out a different hardware is so important. Maybe you could ask your neighbour to lend you his for a while. It only takes minutes to learn a lot.

 

Again, FGT plus straight-through modem is a proven setup. All FGTs that I run rely on this, on ADSL or cable lines.

If you believe that too much experimenting might have botched up the FGT's config then do a factory reset and just set up the interface. No need for policies, DHCP etc. etc. until you know the line will come up.

 

If you can further investigate this, post back on the forum please. Others may be in the same situation. Post the FortiOS version as well.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Dave_Hall
Honored Contributor

Just want to add (was already in the middle of composing a response), was to make sure once you place the DM111PSP in bridge mode to power-cycle it before connecting it to the fgt.  I would make sure that the duplex/speed is correct on the fgt side -- perform a "diag hardware deviceinfo nic <interface name>" on the CLI and check for any errors.

 

I don't know about the DM111PSP, but some modem/gateway devices offer two types of bridge modes which you may need to play with.  I going to assume the MTU value (e.g. 1452, 1492) has already been set properly on fgt for the connection.

 

To set the duplex/speed/mtu on the interface, would be something like this:

 

config system interface
edit "<interface>"
set speed 100full
set mtu-override enable
set mtu <value>
next
end

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
jlozen
New Contributor

Thank you very much for the quick replies. I've edited the original post to include the firmware version. This is at a remote site and will take some time to get some of these suggestions attempted but I'll be sure to add the working solution here once it has been found.

jlozen
New Contributor

It turns out that the Netgear DM111PSP was the issue after all. I can't thank you enough for pointing that out, since the Netgear seemed to be working fine in modem+router mode I don't know how long I would have tried beating my head against the wall trying to get everything else to work right before replacing it. Once I got a new modem put in place everything came up within seconds. Again THANKS SO MUCH ede_pfau!

Labels
Top Kudoed Authors