Skip to main content
Damitha
New Member
August 21, 2017
Question

Random Network Failures

  • August 21, 2017
  • 8 replies
  • 15343 views

Hello

 

I am experiencing a strange issue with Fortigate 600C firewall. Time to time whole network is disconnect and reconnect within 3-5 secs. There is no any ping drops. But all the user sessions are dropping. (eg. Internet, SAP users, IPPhones, etc..)

The unit was on FortiOS 5.2.5 and I have upgraded it to 5.2.11 (5.2.5 -> 5.2.7 -> 5.2.9 -> 5.2.11) also changed the hardware too. (Tried different FG 600C unit) But still unable to find the cause to this issue. Please assist me to identify this issue.

 

Thank you

Damitha 

8 replies

rdesilva_FTNT
Staff
Staff
August 21, 2017

Hi Damitha,

There can be many reasons why users/services experiencing dropouts.

1.During the outage, can you access other networks that are directly connected to the Fortigate, apart from the Internet link?

2.Do you see the same issue if you bypass the Fortigate?

3.The affected services, are they routed via a IPSec VPN ---> Datacenter ---> Internet or is it a direct link to the internet?

 

Best option will be to raise a support ticket with Fortinet TAC @ https://support.fortinet.com

 

Kind regards,

Rukshan

emnoc
New Member
August 21, 2017

Do you have logging enabled? Can you reviews logs at the time of the event(s)?

 

Since you changd hardware, changed code, what else do you have in  the network path?

 

Also what do you mean exactly by

There is no any ping drops. But all the user sessions are dropping. (eg. Internet, SAP users, IPPhones, etc..)

 

 

If you have applications failing, run diagsnotsic or logs against the application and  look for similarities  (  SIP registeration timeouts for example....)

 

 

Damitha
DamithaAuthor
New Member
August 21, 2017
Since the outage is less than 5 seconds it is very hard to troubleshoot. But we started continues ping to internet, internel servers, other internel networks and during the outage there is no any timeouts. But SAP user sessions are disconnected. Same for the IP phones, FortiWiFis... There are no IPSec VPNs. All the network segments are directly connected to the firewall. And 1 trunk port which has about 5 vlans. All the routing and access handled by the firewall itself. There are no any event logs related to this. There were some logs related to webfilter, appfilter memory logs. I have disabled the memory logs for sometime, but the issue happened. The unit has 3 VPN links, 3 Server Segments, 2 FortiWiFi subnets, 1 Trunk Port (all user VLANs), and 2 internet links configured for Wan link load balancing.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!