Skip to main content
arleniscg
Staff
Staff
March 11, 2025

Technical Tip: Troubleshooting IPsec VPN packets drops after upgrade to version 7.0.3

  • March 11, 2025
  • 0 replies
  • 536 views
Description This article describes the troubleshooting steps if traffic over IPsec VPN show drops or stops working after the FortiDDoS upgrade to version 7.0.3.
Scope FortiDDoS F.
Solution
  1. Take a sniffer L6 on the Firewall and validate if UDP traffic is sending 0x000. Note that the checksum of empty UDP packets is required to be 0xfff, as FDD is inspecting after the upgrade also this type of packet if the firewall is sending the wrong format, will be required to adjust on FortiDDoS, only on the Firewall-SPP.

IP Profile. See: IP Profile Overview - FortiDDOS-F handbook to disable these options and test VPN.

*UDP Empty Checksum Check (disable this option).

*IKE Strict Anomalies (disable this option).

*Tunnelling Attacks (disable this option).

 

Note:

On the rest of the SPP, keep this option enabled.

 

  1. If the problem is still present, adjust the IPsec-related sys_reco value related to port 50, 4500. 

     

 

FDD1.png

 

FDD0.png

 

  • Delete it, then create a custom for this specific IPsec port and adjust the value as required. 

 

FDD3.png

 

Note:

Validate logs/drops on Layers 3, 4, and 7 related to UDP/Firewall-SPP to decide if a large threshold is required.

 

  1. If the problem is still present, open a case with the Fortinet TAC Team (Technical Tip: FortiDDoS commands to open a new ticket to TAC).