Skip to main content
Asad_Khan
New Member
March 8, 2015
Question

dpd_failure & esp_error - ipsec tunnels dropping all traffic pakcets

  • March 8, 2015
  • 6 replies
  • 39284 views

We have Fortigate 100D. IPsec site to site tunnels were working fine. but suddenly ipsec tunnels stop passing traffic and ipsec client users were also unable to connect or getting disconnected after 1 minute. I checked the logs & reports > Event Logs > VPN; there i noted some error in vpn phases i.e. dpd_failure, esp_error etc.

Then without any changes in configuration i restarted fortigate, and every thing was fine then

But i want to find the root cause for this to avoid downtime in future cause my company can't bear downtime.

Please find the attached image for error details. Please find out what was the root cause for this problem.

 

Regards,

Asad Khan

---------------------------

FCNSA, CCNA, MCSE 2012

 

    6 replies

    ralphian08
    New Member
    April 7, 2015

    HI Khan

     

    Have you resolved this fortigate vpn tunnel issue?..

    Nihas
    New Member
    April 8, 2015

    Hi , 

    This could be a bandwidth issue.

    Dead Peer Detection (DPD) always check the availability of Remote peer and if find any problem with the accessibility it will bring down the tunnel once  the threshold value reaches.

     

    Check the latency to any of the internet destinations while you face the problem. There is no other reasons for the outage especially you have mentioned that, during the time IPSec Client users also had the same problem. I would suggest to keep your eye on the band width utilization of the link which you are using for S2S and C2S IPSec VPNs.

     

    Thanks

    Nihas

    Asad_Khan
    Asad_KhanAuthor
    New Member
    April 8, 2015

    Yes................Restarting the Fortigate is a solution only................

    And regarding that esp_error, Fortinet TAC is saying that it is a known bug.

    But After restarting unit, it didn't happened again, though i can still see the errors notification in the logs a about every day.

     

     

    Asad_Khan
    Asad_KhanAuthor
    New Member
    April 8, 2015

    Hi Nihas,

    You are right. But at the time of issue, i checked the bandwidth & ISP (internet) line first. It was ok. For internet line there was no drops. I can surely say that Bandwidth was ok at the time of issue.

    There are many things so are not sure about some specific one. It is the Fortinet TAC who should point out the root cause.

     

     

    Nihas
    New Member
    April 8, 2015

    Yea.. I understand. :)

    I too had faced the similar kind of issues with my VPN's.

    It was all about either the internet link problem or the remote peer IP reachability problem.

     

    While restarting the box , all sessions will close and the band width pool becomes free.  So the tunnel wouldn't have any problem to re-establish the connectivity.  That's the basic logic behind on this specific issue.. !

     

    Let's wait to hear the expert opinion from TAC guys.

     

    Cheers..

    Nihas

     

    Iz3k34l
    New Member
    April 13, 2015

    I was also lead to believe it could be an encryption problem, like the encryption was too high which slowed things down under a large amount of throughput and caused these problems... maybe someone can confirm

    thanson
    New Member
    December 6, 2016

    We have 2x100D in HA(fw v5.0.9) with "low" throuput (10-5 Mbit/s) and this bug occured after 489 days of uptime.

    Our support admin denied the root of the problem with 100d at first. After reboot ihe ip-sec far-ends immediately connected perfectly.