Tuesday, June 1, 2021

Cisco SG250 "Drop Events" on uplink port

Greetings

Sorry in advance if this isn't "enterprisey" enough but it's what we have in this office. If I should ask this somewhere else, let me know and I'll do that.

I have a Fortigate 60F (6.0.12) feeding into a Cisco SG250-50 (2.5.0.83), both of which are brand-new in the last 90 days. The Fortigate is plugged directly into an ISP-provided Hitron cable modem, attached to a 1G/50M service.

We are seeing inconsistence in our service. Speed tests can range anywhere from 50/5 to 950+/55. Days can go by without performance issues, and then we'll have days where the voip will get choppy/drop-happy/one-sided etc, and/or teams video will be laggy and choppy and freezy.

Speedtest issues do not correlate to the other issues.

Vendor support has been, so far, hopeless.

The only outlier that I can put my finger on, and that only inconsistently, is that when the speedtest results are bad, the switchport connected to the firewall LAN interface will sometimes accumulate RX Discards (called Drop Events in the web GUI) during the speedtest. As in, 10K to 15K packets per test run.

These results happen only when the speedtest is run through a web browser, connected to either speedtest.net or "whatever it is google uses when you search for speed test". If I use the win10 Speedtest.net App, it does not accumulate drop events, bad result or good.

Also, speedtest results are much less likely to be bad when run through the app.

Also, drop events do very slowly accumulate during non-speedtest use, but only in the order of a couple dozen per day.

My research suggests that drop events (InDiscards) indicate that the switch received a packet and did not forward the packet on -- due to ACLs (none active), QoS (default setting but the port shouldn't be triggering it) or a lack of resources on the switch -- ie buffer space. I can't rule out the last one, becuse I have been unable to find a guide to debug-mode on this switch (if debug-mode on the switch would even help diagnose something like this).

If I move the uplink port, the discards follow the move. So there's something about the way that this firewall talks to this switch.

Except, as I mentioned, both these devices are new in the last 90 days. The previous firewall, a FortiWifi 60D (6.0.8) was connected to an HP 1810G-24, and we saw the same kind of performance issues. I can't tell you if the "discard" symptom was showing because those HP switches don't export crap through SNMP. The intermediate combination, the FortiWiFi 60D connected to this Cisco SG250, also exhibited the same performance problems.

Every cable I can lay my hands on has been replaced. Both the switch and the firewall have been replaced. I can't see any evidence of ip conflicts or mac stealing. The only pre-existing "neworking" equipment still here are a pair of Aruba Instant Network things, and to simplify things I've turned them off while we work on fixing the wired network issues. And still.

Further upstream, the ISP has been in and replaced an open splitter on the input cable with a straight coupler. When they (or we) plug directly into the ISP device, the performance is always good.

I'm losing my mind here. At this point I'd welcome someone rolling up and saying the equivalent of "You idiot, have you set the [obvious parameter] from [broken] to [working]?" because it would just get this issue off my back.

What should I look at next?

Guidance gratefully appreciated. Thank you.



Inter-VLAN Routing with multiple sites and L3 devices

Hello!

This may be too basic but I have run into an issue wherein I may be over-complicating things.

TL;DR - User cannot ping/upload/download/access data from their device (D1) in VLAN (a) to another specified device (D2) in a VLAN (b). Our internal DNS lists the sought-after device with. There are two L3 switches (ip routing enabled on both) that connect back to another L3 switch acting as our gateway. Each of the VLANs have /24 subnet to help demarcate traffic.

The Specifics: The user's device is connected to a L2 switch -> L3 Switch (Distro) -> L3 (Core) -> L3 Switch 2 (Distro) -> L2 Switch 2 -> ((Sought-After Device)). The L2 SWs are HP and not tagging traffic. L3 Distros are Cisco Catalyst 3750X and L3 Core is Cisco Catalyst 9400. All L3 switches have matching VLANs and IPs assigned to each VLAN for every device. I can't even seem to get a DHCP address when I connect to the switch directly tied into D2.

Is it possible that there are 'too many cooks' given the IP routing capabilities of the core and distro switches?

If this questions is inappropriate please delete!

Thanks for all you have taught me so far!



Cisco 2960s

Anyone still got these in prod? Was thinking of grabbing one from ebay as a spare? we don't have vlans so i think it would be a safe spare. Thoughts?



More SFP converter in a network

Hi!

I would like to ask a question about a small factory network. I was learning networking 10 years ago, working on a cnc machine, and my boss asked me if this will works.

We would like to use 5 TP-Link MC220L.

We have 4 switches that does not have a SFP module.

If we buy 4 MC220L and we connect them with the switches, will it work? (let me try to explain)

Switch1 ethernet to MC220L(1) Ethernet

MC220L(1) SFP to MC220L(2) SFP

MC220L(2) Ethernet to Switch2

Switch2 ethernet to MC220L(3) ethernet

MC220L(3) SFP to MC220L(4) SFP

MC220L(4) Ethernet to Switch3

Switch3 ethernet to MC220L(5) ethernet

MC220L(5) SFP to MC220L(6) SFP

MC220L(6) SFP to Switch4

Or is this totally pointless.

We got optical internet some days ago, and the network is not builded yet. My boss wants to build the network cheap AF.

Thanks for the helping.

A forgetful network specialist



Fiber Question

Does fiber connector color matter at all? If I have a multi mode fiber cable, multi mode SFP 10G (both ends), and using LC connector on both end points. I would assume I’m good to go?



FTD with FPR

Anyone know of a really good place to get information on the FTD system, specifically using the FPR device line? the Cisco documentation is pretty non-descript on a lot of items. I've fumbled my way through the learning curve so far. I can't seem to figure out how to ping the inside interface of my FPR devices from inside hosts. I can hit the management IP no problem. I can route traffic through the device no problem.

I've setup ACP rules to permit ICMP, I've set the platform options to allow ICMP and created a policy there as well. It worked until I put the first ACP on the device. one place I read said ICMP is open by default so since I'm not explicitly blocking it why can't I hit it?



Port Mirror without losing network access

Up until now, I have been plugging my laptop in and outputting the mirrored port to the interface the laptop is connected to on the switch. Since we have started working remotely, there have been a few times where I need to port mirror from several switches away. So laptop > PC in office > office switch > access switch > core. I need to capture traffic from a port on the core. Is there any way to do this without killing the remote connectivity. Do I need another device to output to? How does that device retain connectivity?



Unifi switch for data center

Any concerns from anyone about using a unifi (usw-24) as a core switch in our data center? When I say core, I mean it'll connect our firewall to our vsphere esx environment. The controller is hosted on a vm on that esx environment, so my concern is FW upgrades as the esx servers will go offline for a few mins when that occurs. Anyone else doing this? Unifi doesn't make stackable switches like my old Dell stuff was. Thoughts? Comments?



Network Management

What do you use for monitoring your network? More specifically is there any software that can make backups of the configs daily and compare any changes that might have happened? Looking at Solarwinds, PRTG and Open engine.



Fluke Etherscope II software archive?

I recently acquired a working Fluke networks etherscope II, it didn't come with any software and was wondering if it was up to date. It is version 5.0.02.
Please hit me up if you know of any software archives for this unit, or if I am already at the latest firmware. Thanks!