[v6.0.1, v5.6.5, v5.4.9] FortiOS Cook & Research

v5.2對於僅有internal-flash的FGT將會移除log-disk support...
注意這個差別! 這不是bug...
Disk logging and memory logging changes
On some FortiGate models, flash-based logging is not available in FortiOS v5.2.0. For these
platforms, Fortinet recommends the free FortiCloud central logging & reporting service, as it
offers higher capacity and extends the features available to the FortiGate. These models
include:
• FG-100D (P09340-04 or earlier)
• FG-20C
• FG-20C_ADSL_A
• FG-200B/200B_POE (Without FSM)
• FG-300C_Gen1 (P09616-04 or earlier)
Upgrading to FortiOS v5.2.0 build 0589 Page 19 FortiOS v5.2.0 Release Notes
• FG-40C
• FG-60C
• FG-60C-POE
• FG-60C-SFP
• FG-70D
• FG-60D
• FG-80C/80CM (P05403-05, P05446-05)
• FW-20C
• FW-40C
• FW-20C_ADSL_A
• FW-60CX_A
• FW-60C
• FW-60CM (P08962-04 or later)
• FW-60CX_ADSL-A
• FW-60D
• FW-60D-POE
• FW-80CM (P05405-06 or later)
v5.0,build0271不知道能不能直接升,因為我現在有兩條wan,頻寬差距還還大的,但頻寬大的那條,使用率卻只有60%左右,想試試新的看看能不能在正常狀況,把大頻寬的部分使用率再拉高。
另外在vlan外,想來玩看看
vxr wrote:
FortiOS v5...(恕刪)

crazyking wrote:
v5.0,build...(恕刪)

你是使用甚麼FGT?..
我目前用100d,有做HA
謝謝
vxr wrote:
你是使用甚麼FGT?...(恕刪)
v5.2 GA其中一項重大改革就是全新的FortiView...
這是比起以往來說極為強大的Traffic Monitor...
從如下畫面就可以看出這是以往Monitor所不能比的..

它包括了歷史監控以及即時監控...
歷史監控(即時, 5mins, 1hr, 24hrs)代表著永續性的日誌紀錄..
提供了所謂的historical data page架構
這表示他需要一個固定的儲存媒體....
可惜的是僅有Internal FLASH的FGT機種無法支持historical data page...
From Fornit Engineer's reply:
"only disk logging with SSD/HDD supports this feature for now???"
Yes:-
* If the unit has an SSD, but disk logging is not enabled, they will be prompted to enable disk logging

* If the unit does _not_ have an SSD, none of the historical FortiView pages will be available

目前可惜的是它還不是很穩定...
運行的過程中有可能會有如下類似的log:
Pid: 00062, application: pyfcgid, Firmware: FortiGate-200B-POE v5.02.0,build0589b589,140613 (GA) (Release), Signal 11 received, Backtrace: [0x0843535a] [0x0845db4e] [0x084d78a3] [0x084d9187] [0x084ede78] [0x084b8701] [0x0851f00a] [0x085205ff] [0x084d452f] [0x084b8701] [0x0851f401] [0x0851ee56] [0x085205ff] [0x084d452f] [0x084b8701] [0x084c363c] [0x084b8701] [0x084f4c8c] [0x084b8701] [0x0851f00a] [0x085205ff] [0x0851eebf] [0x0851ee56] [0x0851ee56] [0x0851ee56] [0x0851ee56] [0x0851ee56] [0x0851ee56] [0x0851ee56] [0x085205ff] [0x084d452f] [0x084b8701] [0x084c363c] [0x084b8701] [0x0851f00a] [0x0851ee56] [0x085205ff] [0x0851eebf] [0x085205ff] [0x084d452f] [0x084b8701] [0x0851f401] [0x085205ff] [0x084d452f] [0x084b8701] [0x0851f401] [0x0851ee56] [0x0851ee56] [0x085205ff] [0x0851eebf] [0x085205ff] [0x0851be3f] [0x08535612] [0x085355ca] [0x08534bb9] [0x084a4250] [0x082ba85b] [0x08076072] [0x08075ba4] [0x0807432f] [0x080758b0] [0x08073c6f] [0x400bf3e5] [0x08073cf1]


並且這個運作的GUI process會幾乎殺掉(kill) CPU和記憶體..
在這時必須要操作如下命令把該process給銷毀:
diag sys kill [NUM] [PROCESS_ID]

crazyking wrote:
我目前用100d,有...(恕刪)

你目前有多少條的policy??...
基本上是可以從5.0.7直升...

你是哪個版本的100D??
可否操作如下CLI命令提供相關資訊?
get hard status
policy才設5條,4月剛上線而已。
Model name: FortiGate-100D
ASIC version: CP8
ASIC SRAM: 64M
CPU: Intel(R) Atom(TM) CPU D525 @ 1.80GHz
Number of CPUs: 4
RAM: 3959 MB
Compact Flash: 1917 MB /dev/sdb
Hard disk: 30533 MB /dev/sda
USB Flash: not available
Network Card chipset: Intel(R) PRO/1000 Network Connection (rev.0000)
Network Card chipset: bcm-sw Ethernet driver 1.0 (rev.)
謝謝
vxr wrote:
你目前有多少條的po...(恕刪)
crazyking wrote:
policy才設5條...(恕刪)

只有5條..
想要就直升吧...
如果說有100多條那就要考慮了, 因為光整理會很花時間..
5條就別想太多了...
你這是gen2以上的版本...

你必須要善用100D的一些 "獨特的硬體機能" 來保持甚至改善網路效能...
就是有聽說forti的機器不錯,才弄了兩台做HA,不過現在機器都在線上,想玩一些東西找不太到資料,也怕沒弄好整個網路會大亂,那就很精彩了,之前好像有看到,可以下載OS在PC上測,可是一直找不到。
vxr wrote:
只有5條..想要就直...(恕刪)
Application Control雖然進行了改革..
不過他犯了一些缺失..
最主要的是客製化App篩選使用上變得相當麻煩...


比方說我要篩選P2P的App簽章, 發現需要的有20個..
那問題就來了, 確實篩選了這個20個..
但是我得改20次設定...

這比起5.0.x設計上變得難以使用, 除了帶來嚴重困擾也不清楚開發團隊在想甚麼...
文章分享
評分
評分
複製連結
請輸入您要前往的頁數(1 ~ 69)

今日熱門文章 網友點擊推薦!