Producent oprogramowania Fortinet udostępnił najnowszą aktualizację dla FortiSwtich o oznaczeniu 7.2.1. Dzięki temu poprawiono problem związany z aktualizacją z niższej wersji do 7.2.0, gdzie próba kończyła się niepowodzeniem i wyświetlanym komunikatem ,,OUT OF MEMORY: KILL PROCESS’’. Ponadto nowsza wersja naprawiła problem z błędnym działaniem usługi DHCP snooping, która występowała po restarcie urządzenia. Od 7.2.1 dodano nową stronę Router > Multi-Traceroute, która pozwala na wykonanie technologii traceroute. Aktualizacja również pozwala na zmianę priorytetów dla uwierzytelnienia MAC(MAB) i EAP 802.1x. Po więcej szczegółowych informacji zapraszam do dalszej części artykułu.
Co nowego w FortiSwitch 7.2.1:
- Technologia VXLAN jest obsługiwana na jednostkach FS-1024E I FS-T1024E
- Możesz teraz używać routowanego interfejsu VLAN (RVI) jako inicjatora tunelu VXLAN lub miejsca docelowego tunelu VXLAN.
- Możesz teraz skonfigurować wirtualny routing (VRF) oparty na portach dla RVI.
- Teraz można używać trybu dynamicznego klucza (CAK) dla zabezpieczeń Media Access Control (MACsec).
- Możesz teraz używać interfejs CLI do zmiany priorytetu uwierzytelniania MAC (MAB) i uwierzytelniania Extensible Authentication Protocol (EAP) 802.1X.
- Nowa strona Router > Multi-Traceroute umożliwia uruchamianie traceroute w GUI. Wyniki są wyświetlane w formie wykresu i tabeli.
- System > FortiLAN Cloud raportuje teraz usługę wysyłki, usługę dostępu, status weryfikacji SSL oraz przyczynę ostatniego restartu.
Aktualnie wspierane modele:
FortiSwitch 1xx | FS-108E, FS-108E-POE, FS-108E-FPOE, FS-108F, FS-108F-POE, FS-108F-FPOE, FS-124E, FS-124E-POE, FS-124E-FPOE, FS-124F, FS-124F-POE, FS-124F-FPOE, FS-148E, FS-148E-POE, FS-148F, FS-148F-POE, FS-148F-FPOE |
FortiSwitch 2xx | FS-224D-FPOE, FS-224E, FS-224E-POE, FS-248D, FS-248E-POE, FS-248E-FPOE |
FortiSwitch 4xx | FS-424E, FS-424E-POE, FS-424E-FPOE, FS-424E-Fiber, FS-M426E-FPOE, FS-448E, FS-448E-POE, FS-448E-FPOE |
FortiSwitch 5xx | FS-524D, FS-524D-FPOE, FS-548D, FS-548D-FPOE |
FortiSwitch 1xxx | FS-1024D, FS-1024E, FS-1048E, FS-T1024E |
FortiSwitch 3xxx | FS-3032E |
FortiSwitch Rugged | FSR-112D-POE, FSR-124D |
Rozwiązane problemy:
Bug ID | Description |
---|---|
793821 | A “Failed to send l2mac trap” message is reported if log-mac-event is enabled on one port without the SNMP-related information being configured. |
795444 | The performance of the Switch > Monitor > Forwarding Table page needs to be improved. |
796655 | The Switch > Monitor > 802.1x Status page does not sort the MAC addresses correctly and does not display VLAN traffic. |
796779 | The Switch > Monitor > IGMP Snooping page does not display IGMP groups. |
796806 | The set cfg-save revert command under config system global now reboots the FortiSwitch unit after waiting the number of seconds configured in the set cfg-revert-timeout command. |
797735 | The diagnose sys performance status command should not be available. |
798357 | When multiple VXLAN configurations use the same remote-ip value, the VXLAN tunnels do not update the underlying SVI IP address. |
802529 | After rebooting a FortiSwitch unit, IP source guard with DHCP snooping does not work. |
802786 | Virtual IP addresses cannot be used in a FortiGate device to redirect the public IP address to the private IP address of the FortiSwitch unit. |
803112 | Customizing the HTTPS port does not work. |
803579 | The “port24 Overload state. POE disabled” message appears in the log every hour. |
807291 | After updating the FortiSwitchOS 7.2.0, the switch fails with an “Out of memory: kill process” log message. |
Znane problemy:
Bug ID | Description |
---|---|
382518, 417024, 417073, 417099, 438441 | DHCP snooping and dynamic ARP inspection (DAI) do not work with private VLANs (PVLANs). |
414972 | IGMP snooping might not work correctly when used with 802.1x Dynamic VLAN functionality. |
480605 | When DHCP snooping is enabled on the FSR-112D-POE, the switched virtual interface (SVI) cannot get the IP address from the DHCP server.
Workarounds: |
510943 | The time-domain reflectometer (TDR) function (cable diagnostics feature) reports unexpected values.
Workaround: When using the cable diagnostics feature on a port (with the |
542031 | For the 5xx switches, the diagnose switch physical-ports led-flash command flashes only the SFP port LEDs, instead of all the port LEDs. |
548783 | Some models support setting the mirror destination to “internal.” This is intended only for debugging purposes and might prevent critical protocols from operating on ports being used as mirror sources. |
572052 | Backup files from FortiSwitchOS 3.x that have 16-character-long passwords fail when restored on FortiSwitchOS 6.x. In FortiSwitchOS 6.x, file backups fail with passwords longer than 15 characters.
Workaround: Use passwords with a maximum of 15 characters for FortiSwitchOS 3.x and 6.x. |
585550 | When packet sampling is enabled on an interface, packets that should be dropped by uRPF will be forwarded. |
606044/610149 | The results are inaccurate when running cable diagnostics on the FS-108E, FS-124E, FS-108E-POE, FS-108E-FPOE, FS-124E-POE, FS-124E-FPOE, FS-148E, and FS-148E-POE models. |
609375 | The FortiSwitchOS supports four priority levels (critical, high, medium, and low); however, The SNMP Power Ethernet MIB only supports three levels. To support the MIB, a power priority of medium is returned as low for the PoE MIB. |
659487 | The FS-124F, FS-124F-POE, and FS-124F-FPOE models support ACL packet counters but not byte counters. The get switch acl counters commands always show the number of bytes as 0. |
667079 | For the FSR-112D-POE model:
|
673433 | Some 7-meter DAC cables cause traffic loss for the FS- 448E model. |
748210 | The MAC authentication bypass (MAB) sometimes does not work on the FS-424E when a third-party hub is disconnected and then reconnected. |
784585 | When a dynamic LACP trunk has formed between switches in an MRP ring, the MRP ring cannot be closed. Deleting the dynamic LACP trunk does not fix this issue. MRP supports only physical ports and static trunks; MRP does not support dynamic LACP trunks.
Workaround: Disable MRP and then re-enable MRP. |
793145 | VXLAN does not work with the following:
|
795041 | The VM debug report (System > Debug Report) is missing information for many CLI commands. |
Notatki producenta: FortiSwitch 7.2.1
Pozdrawiamy,
Zespół B&B
Bezpieczeństwo w biznesie