Skip to main content
RolandBaumgaertner72
New Member
September 25, 2024
Question

FG60F with SD WAN Packet Loss Failures

  • September 25, 2024
  • 13 replies
  • 5840 views

Hi,

 

this FG60F with 7.4.5 (before 7.4.4 and same problems) has lots of problems with SD WAN.

 

Today I was there to ceck internet access and SD Wan config but I cant solve the problem. The SD WAN is strange, like at least 2-3 times a week and than for some hours one of the WANs has 30-80% package loss. Also than navigating behind the FG you notice the problem when you are using WAN x at this moment.

 

At the same time that the FG showed 70% package loss, I connected my laptop behind the router and checking with pings and internet speed test the line for >20min and NO problem at all. Again connecting to the FG I get package loss. I changed even the cable to be sure.

 

The SD Wan config is simple, one implicit rule sessions 50-50 and Performance SLA to ping Cloudflare 1.1.1.1 and 5-5-10-500-5-5 all activated.

 

What can be the reason of these package loss showing in the FG? Also I have fortiddns over WAN1 and when it shows package loss, I have problems connecting from outsider to the FG.

 

Thanks!

13 replies

adambomb1219
SuperUser
SuperUser
September 25, 2024

Speed/duplex settings?  

RolandBaumgaertner72
New Member
September 26, 2024

Hi,

 

i checked and updated realistic data from the ISP.

 

Again today we get package loss with the new line and again behind the router everything is fine.


I dont get it, why does the FG show package loss if ther shouldnt be any. Thats a big problem, SD WAN in this customer is working really bad

 

Thanks

adambomb1219
SuperUser
SuperUser
September 26, 2024

What do you mean "realists data"?  What is package loss?

RolandBaumgaertner72
New Member
September 27, 2024

Hi,

 

it is just not working fine. The FG starts with showing package loss in SD WAN Performance Status (from 10-75%) which is not correct because if I connect to the router and start diagnosing I can ping and whatever. 

 

Than users get problems, especially users on the wifi since I thing that if the AP is on the package loss line, the user switches to another AP and than everything just gets worse.

 

Also I see package loss like 50% on WAN2 and we have like 3 VPNs over WAN2 and they are working, traffic is passing (Camaras).

 

Yesterday I changed to all traffic on WAN1 with SD rule and no package loss on both WANs (the other one is used for VPNs).

 

Thanks

 

 

RolandBaumgaertner72
New Member
September 30, 2024

Hi,

 

this morning I have another FG60F with 7.0.15 with problems with 2 WANs in SD WAN. Both show package loss.

 

This is getting really serious, I am sure that the internet access is fine.

 

Thanks

Marco_P
New Member
September 30, 2024

Try setting the healtcheck / sla protocol to "DNS" instead of ping.

We had some issues in the past with ping only to public DNS destinations (I think it was provider related).

 

It's maybe also a good idea to add a second server as target.

RolandBaumgaertner72
New Member
September 30, 2024

I have 2 sites now, I changed from AWS and Office.com to 2 spanish DNS servers and it is the same. Pinging both of them directly from the FW I dont get package loss, but like 300ms and more.

RolandBaumgaertner72
New Member
October 3, 2024

Hi,

 

is there a known issue about SD WAN in 7.4.5?

 

I have big problems with this config. I changed SD WAN Rule so that ALL are using interface WAN1 just to have some time and thinking that it cant fail. I suppose that without SLA it should just work with this route but yesterday again I had both WANs down. One of them is using VPNs and access to cameras and VPN and cameras were UP all the time.

 

First of all, using on top the SD WAN rule for WAN1 the SLA Performance should not affect any downside of the WAN, correct?

 

What can be the cause and problem that like 2-3 times a week both internet accesses are gone for the FG but I know for sure that they are working fine.

 

My SLA performance rule is normal to 1.1.1.1 and 1.0.0.1 ping with standard values.

 

Thanks!

Brunn3r
Explorer II
October 3, 2024

ask your provider what MTU Setting you should use and configure as told.

Also consider a downgrade to 7.2.9/7.2.10 if this is a productive environment: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-Release-for-FortiOS/ta-p/227178

RolandBaumgaertner72
New Member
October 10, 2024

Hi,

 

this afternoon I will downgrade to 6.4.15. Before we had no problems with SD WAN and now we have problems x times per week.

 

We have one fiber access directly connected to the FW which worked fine for years and yersterday it went down. SD Wan is doing really strange things in this firewall and besides of havinf 2 x internet access the client gets offline 2 times a week.

 

From Fortinet Support I didnt hear back.

 

Thanks

Marco_P
New Member
October 11, 2024

Very strange...

 

we're using and setting up SD-WAN for many years, without these issues.  Currently we rollout 7.2.10 (latest major release), some in higher feature releases.  So, 7.2.x should work fine.

 

Are you sure the packet loss is not showing up when there is a lot of in/outbound traffic?  When you reach the limits of your ISP line this loss is normal.

 

Is the config of the Fortigate complex or is it a basic setup?  Can you do a factory reset and re-do the config?  Or if you have a spare FGT, connect that one to the ISP router and configure SDWAN only to do a health-check.

RolandBaumgaertner72
New Member
January 13, 2025

Hello,

 

in this case we still have no solution. We updated to 7.4.6 and we put stitches to solve the high memory and conserve mode problems.

 

Than we tried again activating SD with Loadbalancing over the 2 ISPs. Before we know 100% that both ISPs are working since we use A for all internet traffic and B for VPN connection to remote cameras.

 

Activating again default route for both ISPs everything works fine for 1-2 hours and than ISP B gets down. Before we also changed to our default SD Performance settings:

 

SLA Traget

Latency threshold 250ms

Jitter threshold 50 ms

Packet Loss threshold 5%

 

Link Status

Check interval 500 ms

Failures before inactive 5

Restore link after 5check(s)

 

I dont know why we dont get the SD working in this place.

 

Thanks!

DMS
New Member
October 28, 2025

Hi Roland,

Did you get any solution to this issue? We are also getting the same issue on version 7.4.9. We also have two ISPs and doing a simple load balancing of traffic. Packet loss in ISP link from SDWAN monitoring makes the static route removed one by one for both ILLs. The links work fine if testing directly by connecting to laptop or the Internet switch. 

checked the sdwan config is fine and no int errors at all, just links misbehave in sdwan. 

Thanks in advance. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!