Skip to main content
FrankCQI
New Member
October 11, 2011
Question

Loosing internet connection

  • October 11, 2011
  • 4 replies
  • 4638 views
Here is our setup. Fortigate 60B. Static IP from ISP connected to WAN1 port. We randomly loose connection to internet. ISP modem and router are up and running. Fortigate is up and running, it just doesn' t seem to link our lan with the wan port to acces internet. Any idea what might be causing this? It seem to appen randomly but always around the same time 4-5 AM. Can it be related to fortigate updating itself? Any idea?

    4 replies

    Matthijs
    New Member
    October 11, 2011
    Maybe some script from your internal to internet that causes the fortiwall to go into conserve mode? How do you resolve it? If you don' t power down the unit you could see it in the gui. You can be notified about it: http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD31969&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=24738384&stateId=0%200%2024736499 Also, set the update schedule of the FortiGate to update once a day at 01:00 am to see if this helps ;-) Connecting a console cable to the FortiGate and leave this open to see if there are any errors flowing can also help indicating what is the problem.
    FrankCQI
    FrankCQIAuthor
    New Member
    October 11, 2011
    We resolve it by rebooting the fortigate. I noticed the following log messages when it appen: 73 2011-10-11 05:52:39 critical Ping peer: xxx.xxx.xxx.xxx is down Then our IP sec tunnel drop and internet is no more available until we restart.
    ede_pfau
    SuperUser
    SuperUser
    October 12, 2011
    Then check your WAN interface setup in System>Network>Interface, and look for the section starting with " Detect Interface Status for Gateway Load Balancing" . You have enabled it and chosen a peer server on the other end of the ISP line that is unavailable once a day at around 5 am. You can either - choose a different, known stable server on the internet (like a NTP source) - configure a second ping target (append second IP/FQDN with a space) - disable the Detect Server setup as you only have one WAN line Basically, the Detect Server config helps to quickly delete the default route in case the internet has become unavailable. Otherwise, only a ' Link down' event would trigger this, and that will happen only if you pull the cable from the WAN port. OTOH it doesn' t hurt you much if your FGT does not detect the connectivity loss - traffic will be sent out WAN port but never get replied. Best practice is to enable Detect Server as then the FGT sends out an SNMP trap to your NMS station and you get alerted. Just be careful that you choose a reliable ping target on the ISP' s internal net or close by.
    FrankCQI
    FrankCQIAuthor
    New Member
    October 12, 2011
    Thanks, I will give it a try.
    giovinco_06
    New Member
    January 25, 2012
    Hi FrankCQI, I just want to share that, my fortigate unit 110 C , also got the same problem like u. It will not respond randomly in the morning around 1.00 AM - 5.00 AM. Do you already solve the problem ??