06-23-2022 09:27 PM
We are observing intermediate packet drops in traffic where the cisco C9300-24T is connected to fortigate firewall.
We are using copper port on switch side and sfp-RJ45 at fortigate side.
Need help to resolve this issue. Thanks.
06-23-2022 11:24 PM
Hello,
can you post the output of:
show interfaces x
where 'x' is the interface connected to the Fortigate ?
06-23-2022 11:47 PM
Hi,
We are actually migrating the firewall. The previous firewall had copper port and there were no any packet loss observed.
But the new firewall has all the SFP ports & we are using SFP-RJ45 module for copper connectivity between switch & firewall.
And now we are facing intermediate packet drops in the traffic.
06-24-2022 12:35 AM
Hello,
how do you notice the packet loss ? If there are no drops on the interface(s), do you have a management tool that shows you there is packet loss, or users complaining ?
06-24-2022 12:47 AM
@shantilal wrote:
But the new firewall has all the SFP ports & we are using SFP-RJ45 module for copper connectivity between switch & firewall.
What happens if the connection goes straight to the switch copper ports (bypass/not-use the uplink modules)?
What firmware is the switch on?
06-24-2022 12:51 AM
Switch is directly connected to firewall.
Catalyst L3 Switch Software (CAT9K_IOSXE), Version 16.6.9
06-24-2022 03:18 AM
@shantilal wrote:
Switch is directly connected to firewall.
That's not the answer to my question: You said that the firewall is connected to the switch using a GLC-T module. What happens if the firewall is connected to the switch using the switch's copper ports (and not the SFP ports)?
06-24-2022 12:40 AM
We are facing issue with the new firewall that has SFP ports.
We have used ping for finding drops. The source was behind the switch and destination was behind the firewall.
Source -----> Switch---->Firewall with SFP-RJ45 ------> Destination
06-24-2022 01:03 AM
Hello,
the reason I am asking if the users are actually experiencing problems is that the Fortigate itself might cause the PING drops. According to Fortigate support, the below applies:
"This is an expected behavior: The package is dropped since the ICMP is exceeding the rate limit. The FortiGate team has a limitation for ICMP; the limit is 6 packets per second per sender. This is based on RFC 1812: 4.3.2.8 Rate Limiting A router which sends ICMP Source Quench messages MUST be able to limit the rate at which the messages can be generated. A router SHOULD also be able to limit the rate at which it sends other sorts of ICMP error messages (Destination Unreachable, Redirect, Time Exceeded, Parameter Problem). The rate limit parameters SHOULD be settable as part of the configuration of the router. How the limits are applied (e.g., per router or per interface) is left to the implementor's discretion."
06-24-2022 01:09 AM
Hi Georg,
We have testing the ICMP traffic by bypassing the switch and directly connected two laptops to the firewall but we didn't observed any packet drops.
But If we connect the switch then we observed packet drops. Do we need to check rate limit on the switch side ?
06-24-2022 01:25 AM
Hello,
since you do not see any drops on the interfaces of the switch (show interfaces x), you could use Wireshark or SPAN on the switch to analyze the traffic.
Can you post the output of:
show buffers
from the switch ?
11-23-2022 08:53 PM
Hi Georg,
After a long time, I was checking the issue from the fortigate side but not found any issue yet.
Can you please any command or solution from the switch side. So, I can verify that switch is dropping the packets or not.
Should we use SPAN or any other methods are there ?
We are doing a UAT testing in which we create a separate VLAN in the switch & will connect a laptop & the fortigate for testing the traffic whether any drop observed or not.
Your support will be very helpful for us in the troubleshooting.
Thanks.
11-24-2022 01:33 AM
you can share the show interface in SW
and interface in FW ??
11-24-2022 02:12 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide