Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Max-Payne-WSA
New Contributor

Problem with SFP on ULL ports after upgrade from 7.2.9 to 7.4.5

Hi, due to the transition of software 7.4 to mature status, we decided to update the 401F from version 7.2.9 to 7.4.5.

Unfortunately, after the update, the SFP ports x5-x8 (ULL) have no link.
Downgrading to version 7.2.10 solved the problem.

15 REPLIES 15
dasfliege
New Contributor

We have 601F and now tried several times to upgrade from 7.4.3 to higher versions. We use official Forti SFP28 transceivers, not DAC.

- Update to 7.4.5 failed because ULL ports were down afterwards

- Forti has listed these issues as resolved in 7.4.7 and 7.4.8 (There were two different issues as i understand)

- We tried to upgrade to 7.4.9 today, but still the same issue. ULL interfaces are all down. Also downgrading to 7.4.8 did not solve the problem.

 

I find it absolutely unbelievable that such a major issue still hasn't been fixed after six versions. Upgrading and downgrading across all versions takes around two hours, during which time our entire environment is down. In my opinion this is a major major major issue, since the only working version, 7.4.3 has several highly critical vulnerabilities and we aren't able to update.

dingjerry_FTNT

Hi there,

 

Since you mentioned that there is no DAC with your FGT, it should be a different issue.

 

Please create a ticket and have it reviewed by TAC.

Regards,

Jerry
kbusby

Do you have an update on the status of your issue? I am going to be deploying a very similar topology using 601F's and I'm curious if I will run into the same problems using 7.4.9. 

dasfliege

Feedback from Fortinet was that we have to disable FEC on our switches, since disabling it on the Forti alone does not seem to work. We haven't had the chance to try the update again yet, but will schedule it in the next few weeks.

HarryTran

Hi @dasfliege 

What are your fiber modules and expected speed on the ports?
If you have available ticket number, please share it with me.

HarryTran

Hi @dasfliege 

I ran some tests in the lab on my side using ULL ports at both 10G and 25G, and I wasn’t able to reproduce the issue when upgrading from 7.4.3 to 7.4.5 or 7.4.8.

For reference, here’s the config and transceiver info from my ULL port x7:

 

config system interface
edit "x7"
set vdom "root"
set ip 77.77.77.2 255.255.255.0
set allowaccess ping https
set type physical
set mediatype sr
set snmp-index 33
set forward-error-correction disable
set speed 25000full
next
end

 

FortiGate-601F # get system interface transceiver x7
Interface x7 - SFP/SFP+/SFP28, 100GBASE-SR4 or 25GBASE-SR
Diagnostics : Implemented
Vendor Name : FORTINET
Part No. : FTLF8536P5BCVFTN

 

It might be worth double-checking that your ull-port-mode matches the switch port speed:

FortiGate-601F # show full | grep ull-port-mode
set ull-port-mode 25G

 

If you can share the exact SFP module details on both the FortiGate and switch sides (vendor, part number, speed), I’d be happy to try to mirror your setup more closely and re-test.

 

Regards,
Harry

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors