Technical Tip: Troubleshooting IPsec VPN packets drops after upgrade to version 7.0.3
| Description | This article describes the troubleshooting steps if traffic over IPsec VPN show drops or stops working after the FortiDDoS upgrade to version 7.0.3. |
| Scope | FortiDDoS F. |
| Solution |
IP Profile. See: IP Profile Overview - FortiDDOS-F handbook to disable these options and test VPN. *UDP Empty Checksum Check (disable this option). *IKE Strict Anomalies (disable this option). *Tunnelling Attacks (disable this option).
Note: On the rest of the SPP, keep this option enabled.
 
Note: Validate logs/drops on Layers 3, 4, and 7 related to UDP/Firewall-SPP to decide if a large threshold is required.
|



