Skip to main content
luis-estanga
Visitor III
June 28, 2024
Question

RDP Sessions randomly dropping over IPSEC VPN

  • June 28, 2024
  • 4 replies
  • 3741 views
Hi,

 

We have currently 20 FGT40F branches connecting via VPN IPSEC with the FGT1100E HQ.

Users on the branches connect to a Cluster-RDS via RDP and uses the services/servers from the HQ network.

 

The issue we have is that the RDP sessions are dropping randomly during the day (sometime just once or twice a day) on any branch and sometimes on random hosts.

 

Users on HQ that connects also to the Cluster-RDS never had any complain about connection being dropped, so we assumed that the servers are OK.

 

We performed several troubleshooting steps to try and solve this issue but the problem persists. We took 2 branches to test configurations and if they worked we'd replicate to all the others. So far we tried:

- set auto-asic-offload disable

- set npu-offload disable

- VPN IPSEC: AES-128 and SHA-1 Lifetime:28800s (on both phases)

- system session-ttl for RDP: 28800s

 

Any help would be appreciated.

Thanks

4 replies

hbac
Staff
Staff
June 28, 2024

Hi @luis-estanga,

 

Do you have any security profiles enabled in firewall policies? If yes, you can try disabling them to see if it helps. You can also check the logs at the time of disconnection to see if you can find any drops. It will be useful to collect debug flow and packet captures when the issue occurs: 

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connectivity/ta-p/192560

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Using-the-FortiOS-built-in-packet-sniffer/ta-p/194222

 

Regards,

luis-estanga
Visitor III
June 28, 2024

Hello @hbac 

We have no security services (AV,IPS,SSL,Webfilter, Appcontrol) running on the policies on both sides.

We cannot perform a packet capture because there are so many hosts between all branches and algo because occurs on random times of the day.

Sometimes on the traffic logs we get a server-rst when the user complains but not always. We checked on the server side and we get no error around the time of the drop.

Thanks

Kam1
New Member
July 29, 2024

Hi, 
We encounter the same issue between 101f and 601f firewall in version 7.2.8. 
We have also try to disable the NPU and remove the UTM without success. 


What is the version of your Firewall? 

Regards, 

Kam1
New Member
August 2, 2024

Hi,

 

For information, we have make a rollback in our previous version in 7.2.7 and the issue seems to be fix.

Regards,

HarshChavda
Staff
Staff
August 2, 2024

Hello @luis-estanga ,

 

Can you try to increase default session timeout value. You can refer this document for that

 https://community.fortinet.com/t5/FortiGate/Technical-Tip-Default-session-timeout-value-session-ttl/ta-p/194357