FG-200F / FortiOS 7.4.12 - packet loss / stalls only when NAT-T is enabled (remote access IPsec/IKEv2)
Hi all,
I’m troubleshooting a remote access IPsec issue on a FortiGate 200F running FortiOS 7.4.12 and wanted to see if anyone else has run into something similar.
When NAT-T is enabled, remote users get noticeable packet loss / stalls over the tunnel during normal traffic — pings, file transfers, throughput tests, that kind of thing. When NAT-T is disabled, it gets a lot better.
A few things I’ve already confirmed:
- the tunnel comes up fine
- the issue is reproducible when NAT-T is enabled
- the issue improves significantly when NAT-T is disabled
- I tested with NPU offload both enabled and disabled
- with offload enabled, tunnel error counters were higher on the problematic tunnel
- with offload disabled, those RX errors were much lower or zero in my captures, but the user-visible stalls still weren’t fully explained by the lower-level counters
- PDQ snapshots looked balanced during testing
- HPE dropping stayed at 0 in the snapshots I collected
- anomaly-drop output was empty
- we also contacted our ISP and they ruled out any issues on their side
- this is not happening with just one VPN client — we’re seeing it across multiple VPN clients, so it does not look like a single client ISP / local connection problem
At this point I’m mostly trying to figure out if anyone else has seen FG-200F / SoC4 / 7.4.12 behave badly specifically with NAT-T enabled on IPsec, where the tunnel stays up and traffic partially works, but there are intermittent stalls or packet loss under load.
I already have a TAC case open, so I’m not trying to bypass support — just curious whether anyone else has seen the same pattern, or knows of a bug / workaround related to it.
Thanks.
