12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

System Network<br />

<strong>FortiGate</strong> IPv6 support<br />

Troubleshooting ARP Issues<br />

Address Resolution Protocol (ARP) traffic is vital to <strong>com</strong>munication on a network<br />

and is enabled on <strong>FortiGate</strong> interfaces by default. Normally you want ARP<br />

packets to pass through the <strong>FortiGate</strong> unit, especially if it is sitting between a<br />

client and a server or between a client and a router.<br />

Duplicate ARP packets<br />

ARP traffic can cause problems, especially in Transparent mode where ARP<br />

packets arriving on one interface are sent to all other interfaces, including VLAN<br />

subinterfaces. Some Layer 2 switches be<strong>com</strong>e unstable when they detect the<br />

same MAC address originating on more than one switch interface or from more<br />

than one VLAN. This instability can occur if the Layer 2 switch does not maintain<br />

separate MAC address tables for each VLAN. Unstable switches may reset<br />

causing network traffic to slow down.<br />

ARP Forwarding<br />

One solution to this problem is to enable ARP forwarding. it can be enabled in the<br />

GUI or CLI. In the GUI, go to System > Config > Operation and select ARP<br />

Forwarding. For details on the CLI, see the <strong>FortiGate</strong> CLI Reference.<br />

When enabled, the Fortigate unit allows duplicate ARP packets resolving the<br />

previous delivery problems. However, this also opens up your network to potential<br />

hacking attempts that spoof packets.<br />

For more secure solutions, see the <strong>FortiGate</strong> VLANs and VDOMs <strong>Guide</strong>.<br />

<strong>FortiGate</strong> IPv6 support<br />

You can assign both an IPv4 and an IPv6 address to any interface on a <strong>FortiGate</strong><br />

unit. The interface functions as two interfaces, one for IPv4-addressed packets<br />

and another for IPv6-addressed packets.<br />

<strong>FortiGate</strong> units support IPv6 routing, tunneling, firewall policies and IPSec VPN.<br />

You must use the Command Line Interface (CLI) to configure your <strong>FortiGate</strong> unit<br />

for IPv6 operation. IPv6 configuration is not supported in the web-based manager.<br />

See the <strong>FortiGate</strong> IPv6 Support Technical Note available from the Fortinet<br />

Knowledge Center.<br />

See the <strong>FortiGate</strong> CLI Reference for information on the following <strong>com</strong>mands:<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 115

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!