Skip to main content
bhaskarrao
New Member
May 13, 2024
Question

Getting Packet Drop issue on IPsec VPN Tunnel, after upgrade the FortiOS v7.4.3

  • May 13, 2024
  • 2 replies
  • 4168 views

Dear All.

 

We've encountered packet drop issues on the IPsec VPN tunnel between our FortiGate and AWS after upgrade FortiOS v7.4.3. Disabling the 'NPU Offload' has alleviated some of the packet loss problems, but we're still experiencing frequent packet loss, averaging around 5-6%.

In order to address this persisting issue, could you please provide some solutions or recommendations for resolving it?

 

With regards,

Bhaskar Rao

2 replies

hbac
Staff
Staff
May 13, 2024

Hi @bhaskarrao,

 

Did you try disabling 'replay detection'? There is a known issue with bug ID 1003830. Please refer to https://docs.fortinet.com/document/fortigate/7.4.3/fortios-release-notes/236526/known-issues

 

Regards, 

bhaskarrao
New Member
May 16, 2024

We did disable that option in phase-2, but unfortunately, the issue persists unchanged. We haven't seen any improvement despite our efforts.

 

is there any other workaround to fix this issue.

hbac
Staff
Staff
May 16, 2024

@bhaskarrao,

 

Do you have multiple tunnels going to AWS or just one? You can take packet captures on both sides to see where the packets are lost.

 

Regards, 

ezhupa
Staff
Staff
May 16, 2024

Hello,

What model is your FGT device? 
Is the tunnel between physical FGT and FGT located in AWS?
Any logs being generated on the end devices such as ESP packet errors, HMAC validation errors that coincide with the drops you experience? 
If the device is a F series FGT disabling offloading and replay detection should resolve the issue.

bhaskarrao
New Member
May 17, 2024

Hi, 

The FGT model is 500E and IPsec VPN tunnel between FGT and AWS. 

We tried disabling offloading and replay detection but issue remain same.

 

Please find the log file for your reference.Capture.JPG