Skip to main content
lasale
New Member
February 6, 2026
Question

SDWAN-failover breaks RDP sessions.

  • February 6, 2026
  • 3 replies
  • 320 views

Hello everybody. New to Fortigate NGFW solutions and need some help. I'm running Fortigate 120G HA Active-Passive cluster as a hub and a 70G HA Active-Passive cluster as a spoke. There are two WAN links connecting hub and spoke which are in the SDWAN Global zone + two IPSec tunnels over these underlays which are in the SDWAN Local zone. BGP on loopbacks is the routing protocol I'm using. Point is, I expect RDP between hub and spoke to failover seamlessly when the primary link fails, but each time I try I see session drop, as if conn-reset was sent, although we have quite moderate reconnect timings. As far as I read from fortinet community, when there's a link fail, existing sessions first are being flagged as dirty, then re-evaluated and then considered may-dirty again, no asymmetric traffic issue. How to even approach this problem and where to start debugging? Any suggestions?

3 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
February 9, 2026

Hello lasale, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

Jean-Philippe - Fortinet Community Team
funkylicious
SuperUser
SuperUser
February 9, 2026

hi,

i see that you post on reddit has been also brainstormed by some ppl.

in my opinion and what i've noticed so far with sdwan/vpn, is that a smooth w/o any impact would not be possible even if with the most aggresive timers in bgp/ipsec in order to detect a link failure and have a re-route of traffic.

even running a ping it gets dropped a few packets, so a RDP disconnect would not surprise me but if anyone else knows how to ensure a smooth and w/o traffic disruption i'm eager to hear it.

"jack of all trades, master of none"
AEK
SuperUser
SuperUser
February 9, 2026

Hi Lasale

"Probably" you can do something helpful by enabling auxiliary session.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!