Skip to main content
Nivedha
Staff
Staff
October 4, 2024

Troubleshooting Tip: Packet loss on ADVPN tunnel

  • October 4, 2024
  • 0 replies
  • 1099 views

Description

This article describes how to troubleshoot when packet loss is observed on an ADVPN tunnel.

Scope

FortiGate.

Solution

Step 1: Identify the Source and Destination locations.

Both Source and Destination Behind Spokes (ADVPN not configured for shortcuts):

  • Collect packet sniffer data and debug logs from both spokes and the Hub.

  

Both Source and Destination Behind Spokes (ADVPN configured for shortcuts):

If a shortcut is created:

  • Collect packet sniffer data and debug logs from both spokes.

If no shortcut is created:

  • Collect packet sniffer data and debug logs from both spokes and the Hub.

 

Either Source or Destination Behind Hub:

  • Collect packet sniffer data and debug logs from the spokes and the Hub.

 

Step 2: Collect and Analyze Routing Information, Packet Sniffer Data, and Debug Logs.

  • Routing Table Commands:

 

get router info routing-table details x.x.x.x

get router info routing-table details y.y.y.y

 

  • Packet Sniffer Command:

 

diagnose sniffer packet any 'host x.x.x.x and host y.y.y.y' 4 0 l  

 

  • Debug Commands:

 

diagnose debug flow filter addr x.x.x.x

diagnose debug flow show iprope enable

diagnose debug console timestamp enable

diagnose debug flow trace start 1000

diag deb enable

   

Replace `x.x.x.x` with the source IP and `y.y.y.y` with the destination IP.

 

Step 3: Analyze Logs.

Packet Sniffer Logs:

Check if the logs show traffic exiting the correct IPSec tunnel (look for the 'tunnelname out' phrase) at the source FortiGate:

  • If Yes: Proceed to the next step.
  • If No: Verify if the correct firewall policy is applied (Check debugs flow captured on source FortiGate), and check for SD-WAN configuration and rules if enabled.

 

Check if the logs show traffic entering the correct IPSec tunnel (look for the 'tunnelname in' phrase) at the destination FortiGate:

 

Check if the logs show traffic entering the correct outbound interface at the destination FortiGate:

  • If Yes: Check if the application socket on the destination device is open.
  • If No: Review firewall policies on Destination FortiGate (Check debugs flow captured on destination FortiGate)

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.