Users are reporting intermittent "page not available" type errors on browsers, and I noticed in the switch logs the message "Excessive undersized/giant packets". The two may be unrelated, but the switch message definitely isn't normal.
The switch is a HP Procurve / Aruba 2530 series gigabit switch, and the Sophos XG is configured using an LACP trunk. The switch reports that LACP is active and working on the connected ports.
I have tried several versions of firmware on the switch, including the very latest one, and the messages still persist. Sophos is running XG
The MTU has not been changed from the default 1500 on any device.
The stats on the switch port affected (one of the LACP trunk ports) are:
Errors (Since boot or last clear) :
FCS Rx : 0 Drops Tx : 2
Alignment Rx : 0 Collisions Tx : 0
Runts Rx : 0 Late Colln Tx : 0
Giants Rx : 25 Excessive Colln : 0
Total Rx Errors : 25 Deferred Tx : 0
Which says to me that either the Sophos XG is occasionally sending frames that are too large, or the switch is bad in some way. Because this has occurred on all 4 ports connected to Sophos UTM's (2 ports x 2 XG in HA), I think I can exclude it being a single port or cable fault.
The switch and the Sophos both agree that the ports are all in 1Gb Full Duplex mode.
What else can I check?
thanks
James
This thread was automatically locked due to age.