Skip to main content
UniMK
Explorer
March 20, 2025
Solved

50% packet loss when using "a connection bridge"

  • March 20, 2025
  • 2 replies
  • 756 views

 

Good morning everyone

We are experiencing a strange situation. The following is the scenario.

The user connects via SSL VPN to the head office's fortigate and then, in this connection, with the head office's devices, the packet loss is minimal. However, this SSL VPN connection needs to access a server with an application hosted in a branch office. On this route, the SSL VPN to the head office and from the head office to the branch office has an average packet loss of 50%, sometimes 60%.

Important information: communication between the head office and the branch office is normal, with an acceptable packet loss of only 0.5%.

In short:


User connects via SSL VPN to Fortigate at headquarters
Connection established with headquarters
Packet loss: minimal


User accesses devices at headquarters
Stable connection
Packet loss: minimal


User tries to access server with application at branch office
SSL VPN connection to headquarters
Connection from headquarters to branch office
Packet loss: average of 50%, sometimes 60%

 

Best answer by UniMK

I was part of the established connection, but specifically part of the second phase of ipsec, I created the addresses again with the option marked as active static route.
The strange thing is that both Route Lookup and Policy Match return accepted routes and allowed policies.

2 replies

UniMK
UniMKAuthor
Explorer
March 20, 2025

Important information

Communication between the head office and the branch is normal
Packet loss: acceptable, only 0.5%

And communication between the head office and the branch is carried out by 3 IPSEC internet links using Aggregated Ipsec

and both equipment, head office and branch, use the fortigate 100f

UniMK
UniMKAuthorAnswer
Explorer
March 24, 2025

I was part of the established connection, but specifically part of the second phase of ipsec, I created the addresses again with the option marked as active static route.
The strange thing is that both Route Lookup and Policy Match return accepted routes and allowed policies.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!