03-22-2025 04:35 AM
Hello,
I have core switches 9500 connected to Fortigate 600F
Fortigate owns the layer 3.
When there are just some few devices connected, all is working well
however ,with more clients around 1,000 connected, we start to lost packets and the client encounters disconnections
9500 version. 17.9.2
Do you saw issues in the past between 9500 and Fortinet ?
thanks
Solved! Go to Solution.
03-25-2025 09:18 AM - edited 03-25-2025 09:21 AM
Hello,
thank you so much for your support
Issue is solved
The 9500 is meraki monitored.
This action has created the tracking of all the interfaces included the interfaces towards the firewall.
interface port-channel
device tracking attach-policy MERAKI_POLICY
With a show device-tracking messages, we can observe packet drop on the port channel between the 9500 and the fortinet
The solution is to apply this on all the interfaces especially on the ports towards the gateway
device-tracking attach-policy NOTRACK
03-22-2025 05:11 AM
- What is the traffic load on the Fortigate ?
- Is the Fortigate sufficiently strong to handle the (expected) traffic , according to the specifications of the device ?
M.
03-22-2025 05:44 AM
1000 clients on LAN or Wireless ?
how is your network looks like - Only Cat 9500 alone in the network or any other Lan switches Layer2
check in the path any interface having Interface errors or CRC error,
For testing when you connect device in Cat 9500 in the peak time and client in Lan switch, do some iperf test , what is the outcome ?
03-22-2025 05:49 AM
Let me reply later on this point when i'll have the answer
In the same time, i have an idea. We can see a lot of ARP requests without reply from the switches to the Gateway which is the fortinet. In the captures i saw tcp retransmissions and deduplications
We know that ARP timeout is configured to only 30 sec on fortinet compares to 4 hours on Cisco. The difference is to big and it can be an explenation your idea ?
I think putting 600 sec or 900 sec, same value on forti and cisco side. What do you recommend ?
03-22-2025 12:21 PM
It's all a requirement. Lowering the arp timeout can be an option to set up; it will not harm you. If you like, try that option and monitor it. (but personally do not think that is the issue)
check on the switch CPU and logs on the switch, also CPU and Fortinet (what model ?). What features are used in Fortinet?
But cat 9500 are Core switches, so they should able to handle significant traffic (I have a real-time use case where 20K users use our core, and we do not see that issue)
03-25-2025 09:18 AM - edited 03-25-2025 09:21 AM
Hello,
thank you so much for your support
Issue is solved
The 9500 is meraki monitored.
This action has created the tracking of all the interfaces included the interfaces towards the firewall.
interface port-channel
device tracking attach-policy MERAKI_POLICY
With a show device-tracking messages, we can observe packet drop on the port channel between the 9500 and the fortinet
The solution is to apply this on all the interfaces especially on the ports towards the gateway
device-tracking attach-policy NOTRACK
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide