Skip to main content
martyyy
Explorer III
August 9, 2024
Solved

Traffic being dropped by FortiGate when asic-offload is enabled.

  • August 9, 2024
  • 7 replies
  • 8553 views

Im currently on FortiOS 7.2.8. 

Traffics are being dropped by FortiGate when asic-offload is enabled. To work this out, we are currently set the asic-offload to disable but this is not a long term solution.

 

Is this a bug on 7.2.8? 

https://docs.fortinet.com/document/fortigate/7.2.8/fortios-release-notes/236526/known-issues

 

Does this issue will be resolved in what FortiOS? 7.4.x or 7.2.x ?

 

Appreciate your feedback.

 

TIA :) 

Best answer by Toshi_Esumi

You can at least recreate the situation relatively easily if you temporarily disable "override" (if you have it enabled) and run a command "diag sys ha reset-uptime".
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/666653/primary-unit-selection-with-override-disabled-default
You probably want to do it in a maintenance window.

Redundant interface is different from HA but maybe they have the same mechanism in NP6Xlite. But TAC can tell you if it's the same cause when you open a ticket and ask them to get it evaluated.

Toshi

7 replies

Toshi_Esumi
SuperUser
SuperUser
August 9, 2024

Are you looking at 860460? That involves "a redundant interface". Or 869978? Which involves CAPWAP.
In the end, you have to open a case at TAC to get your situation evaluated to match one of known issues if it's caused by a bug. Then, there maybe a workaround TAC can tell you to try. If no matching, you need to get a bug report created, which you can't do through this community/forum.

Toshi

mpapisetty
Staff
Staff
August 9, 2024

@martyyy ,

I would start with identifying the nature of impact. Is it affecting all traffic? Some type of traffic? Specific policy? Based on that we could narrow down what the issue is and work through a solution. 

martyyy
martyyyAuthor
Explorer III
August 13, 2024

 It is happening on a redundant interface. This interface does not involve CAPWAP tunnel traffic.
The redundant interface is a Layer3 interface (no Layer2)
The firewall is in HA mode and it only happens when we failover to the redundant firewall.

Toshi_Esumi
SuperUser
SuperUser
August 13, 2024

So it's more an HA issue with NPU. What is your model/NPU type? NP7? It's not in the releasenotes under known issues/HA.

Toshi

mle2802
Staff
Staff
August 9, 2024

Hi @martyyy,
Do you have HA pair? I would suggest to open a case with TAC for bug verification to better troubleshooting. 

martyyy
martyyyAuthor
Explorer III
August 13, 2024

The firewall is in HA mode and it only happens when we failover to the redundant firewall.

BillH_FTNT
Staff
Staff
August 9, 2024

Hi,
It would be a big help if you could share more details about your situation :
- What is your device version?
- What is the traffic flow of the issue? Simple topo
- Please share the policy detail
- Do you use sdwan?
- Please share the "dia sys session list" related to the issue traffic (flows)
- Please share the sniffer output or mirror somewhere in your network
- Please share the output of NPU, for example, with NP7 "dia npu np7 dce-drop-all ".
...
Regards
Bill

nathan_h
Staff & Editor
Staff & Editor
August 9, 2024

Hi martyyy,

 

Can you provide your hardware model? We can identify the NPU Chip that you have based on the model. Do you have a packet shaper enabled? You may try to disable it for isolation.

Rajan_kohli
Staff
Staff
August 10, 2024

Hi,

 

Please check if packets are UDP and getting fragmented 

if yes, then follow this kb article:https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-Identify-UDP-NTurbo-fragmentation-drops-and/ta-p/315052

 

if not then please share the hardware model and packet capture

 

Regards

Rajan Kohli

233akkt8g
New Member
August 20, 2024

Hi,

Just curious on what your ultimate fix for this was? Did you end up upgrading to 7.4? 

I'm running into a similar issue on 7.2.8 where TCP traffic stops passing through the Fortigates. When I 'set auto-asic-offload disable' the issue clears. I can replicate my scenario when I see a large increase in sessions over a short period of time.