Producent oprogramowania Fortinet opublikował nowa aktualizacje dla FortiSwitch o numerze 6.2.7. Dzięki nowej aktualizacji, zostały poprawione błędy z wcześniejszych wersji. W nowszej wersji skorygowano problem dotyczy, błędnej komunikacji pomiędzy urządzeniem FortiGate w trybie FIPS-CC a Switchem zarządzalnym, gdzie były problemy z przesyłaniem konfiguracji. W wersji 6.2.7 został naprawiony problem z Fortilinkiem, gdzie utrudnienie dotyczyło błędnej komunikacji z FortiSwitchami w warstwie drugiej i trzeciej, co skutkowało, iż urządzenia były w trybie offline. Po więcej szczegółowych informacji, zapraszam do dalszej części artykułu.
Wspierane modele:
FortiSwitch 1xx FS-108E, FS-108E-POE, FS-108E-FPOE, FS-124E, FS-124E-POE, FS-124EFPOE, FS-148E, FS-148E-POE
FortiSwitch 2xx FS-224D-FPOE, FS-224E, FS-224E-POE, FS-248D, FS-248E-POE, FS-248EFPOE
FortiSwitch 4xx FS-424D, FS-424D-FPOE, FS-424D-POE, FS-424E, FS-424E-POE, FS-424EFPOE, FS-424E-Fiber, FS-M426E-FPOE, FS-448D, FS-448D-FPOE, FS-448DPOE, FS-448E, FS-448E-POE, FS-448E-FPOE
FortiSwitch 5xx FS-524D-FPOE, FS-524D, FS-548D, FS-548D-FPOE
FortiSwitch 1xxx FS-1024D, FS-1048D, FS-1048E
FortiSwitch 3xxx FS-3032D, FS-3032E
FortiSwitch Rugged FSR-112D-POE, FSR-124D
Rozwiązane problemy:
Bug ID | Description |
---|---|
672440 | FortiSwitchOS logs an “Access vlan add failed entry-id” error before FortiLink goes down. |
684986 | When a three-tier FortiLink MCLAG topology was configured, secondary FortiSwitch units in tier-2 and tier-3 go offline unexpectedly. |
685954 | When an Asian language (such as Japanese, Korean, or Chinese) is configured, the browserbased console stops responding. |
692314 | When a FortiGate device is in FIPS-CC mode, it cannot push the configuration to the managed FortiSwitch unit, even when fips-enforce is disabled. |
Znane problemy do rozwiązania:
Bug ID | Description |
---|---|
382518, 417024, 417073, 417099, 438441 |
DHCP snooping and dynamic ARP inspection (DAI) do not work with private VLANs (PVLANs). |
414972 | IGMP snooping might not work correctly when used with 802.1x Dynamic VLAN functionality |
480605 | When DHCP snooping is enabled on the FSR-112D-POE, the switched virtual interface (SVI) cannot get the IP address from the DHCP server. Workarounds: —Use a static IP address in the SVI when DHCP snooping is enabled on that VLAN. —Temporarily disable dhcp-snooping on vlan, issue the execute interface dhcpclient-renew command to renew the IP address. After the SVI gets the IP address from the DHCP server, you can enable DHCP snooping. |
510943 | The time-domain reflectometer (TDR) function (cable diagnostics feature) reports unexpected values. Workaround: When using the cable diagnostics feature on a port (with the diagnose switch physical-ports cable-diag CLI command), ensure that the physical link on its neighbor port is down. You can disable the neighbor ports or physically remove the cables. |
520954 | When a “FortiLink mode over a layer-3 network” topology has been configured, the FortiGate GUI does not always display the complete network. |
542031 | For the 5xx switches, the diagnose switch physical-ports led-flash command flashes only the SFP port LEDs, instead of all the port LEDs. |
548783 | Some models support setting the mirror destination to “internal.” This is intended only for debugging purposes and might prevent critical protocols from operating on ports being used as mirror sources. |
572052 | Backup files from FortiSwitchOS 3.x that have 16-character-long passwords fail when restored on FortiSwitchOS 6.x. In FortiSwitchOS 6.x, file backups fail with passwords longer than 15 characters. Workaround: Use passwords with a maximum of 15 characters for FortiSwitchOS 3.x and 6.x. |
585550 | When packet sampling is enabled on an interface, packets that should be dropped by uRPF will be forwarded. |
Notatki producenta: FortiSwitch 6.2.7
Pozdrawiamy,
Zespół B&B
Bezpieczeństwo w biznesie