timeshifter
Well-Known Member
- Reaction score
- 2,254
- Location
- USA
Got a weird intermittent network issue.
Background: small network with 11 PCs, one Windows Server. FortiGate 60E firewall. Ubiquiti 24 port switch.
Problem: only some users but not always the same users. Since I've been working two users currently having the issue are ones who turn their PC off at night or let it sleep. But not only those two. A different user had the issue today.
So the "bad" PC will have a local IP address. I can ping anything on the local network - the server, a printer, another PC, etc. Cannot ping the gateway or anything past that. Today I had to get one bad PC out of 11 back online. Here's what I tried:
Switching user to different port on switch
Boot PE disk and try connection, behaviour was the same, had same IP address as live Windows
Boot PE disk and manually configure to an available local IP address, no help
Boot back to Windows, no improvement
Install USB WiFi adapter and connect PC that way and all was fine (not a permanent fix of course)
Yesterday I did resets of all network gear, etc. including the switch.
Additional background: this customer just got a new cloud based LOB app that prefers a site to site VPN. Up until a few weeks ago there were no issues. To connect to their app each user had to run Cisco AnyConnect. We changed over to having the firewall handle that with a site to site configuration, as there will be new barcode scanners that require that (and I figured it would be cleaner - ha!).
Old configuration, FortiGate LAN port 1 had a subnet of 192.168.111.0 and no site to site functionality. FortiGate LAN2 port 2 had subnet 192.168.223.0 and was configured with all the site to site stuff. To the best of my knowledge they were otherwise identical.
To switch over the the new LAN2 I simply (mostly) just moved the switch's connection to the firewall from LAN1 to LAN2. And I changed all the devices and settings to the new subnet. I'm somewhat confident this is when the problems started but I think they were more subtle at first.
I'm working on looking at the firewall console, but for some effed up reason I can't find the password, working on a recovery at the moment. Once I have that it might be all fixed in 5 minutes.
But maybe it's a switch issue.
I don't know, my head is spinning and I've typed enough.
Any thoughts are appreciated!
Background: small network with 11 PCs, one Windows Server. FortiGate 60E firewall. Ubiquiti 24 port switch.
Problem: only some users but not always the same users. Since I've been working two users currently having the issue are ones who turn their PC off at night or let it sleep. But not only those two. A different user had the issue today.
So the "bad" PC will have a local IP address. I can ping anything on the local network - the server, a printer, another PC, etc. Cannot ping the gateway or anything past that. Today I had to get one bad PC out of 11 back online. Here's what I tried:
Switching user to different port on switch
Boot PE disk and try connection, behaviour was the same, had same IP address as live Windows
Boot PE disk and manually configure to an available local IP address, no help
Boot back to Windows, no improvement
Install USB WiFi adapter and connect PC that way and all was fine (not a permanent fix of course)
Yesterday I did resets of all network gear, etc. including the switch.
Additional background: this customer just got a new cloud based LOB app that prefers a site to site VPN. Up until a few weeks ago there were no issues. To connect to their app each user had to run Cisco AnyConnect. We changed over to having the firewall handle that with a site to site configuration, as there will be new barcode scanners that require that (and I figured it would be cleaner - ha!).
Old configuration, FortiGate LAN port 1 had a subnet of 192.168.111.0 and no site to site functionality. FortiGate LAN2 port 2 had subnet 192.168.223.0 and was configured with all the site to site stuff. To the best of my knowledge they were otherwise identical.
To switch over the the new LAN2 I simply (mostly) just moved the switch's connection to the firewall from LAN1 to LAN2. And I changed all the devices and settings to the new subnet. I'm somewhat confident this is when the problems started but I think they were more subtle at first.
I'm working on looking at the firewall console, but for some effed up reason I can't find the password, working on a recovery at the moment. Once I have that it might be all fixed in 5 minutes.
But maybe it's a switch issue.
I don't know, my head is spinning and I've typed enough.
Any thoughts are appreciated!