Skip to main content
mikevan
New Member
May 13, 2005
Question

vpn packet loss

  • May 13, 2005
  • 9 replies
  • 8113 views
Hello, I currently own several fortigate 60' s and I am experiencing packet loss in a VPN tunnel. I lose about 1% of my packets. I moved from AES128 encryption to 3DES and that seems to make it more stable but I still lose packets. I also prioritized the traffic on the tunnel. I thought maybe that it could be a ids problem but I have two subnets (SA' s) on the same tunnel and I will lose packets on one but not the other (at least not at the same time.) Is there a setting that may be causing this? Mike

    9 replies

    UkWizard
    New Member
    May 13, 2005
    more than likely to be a network problem somewhere, like with your isp. Are both ends of the tunnel fortinets ? check there settings are exact. other thing you could do is set continuous pings to the firewall at the remote site, and a host at the remote site, and see whether they both drop off or just the vpn one. If they both drop off, its probably your isp connection.
    mikevan
    mikevanAuthor
    New Member
    May 17, 2005
    Thanks for the input but it is definately not the ISP. As I had noted before, I have two separate tunnels terminating on the one link with different subnets. When I constantly ping a node through the tunnels at each subnet I get request timed out on one but not the other. I made some changes to prioritize the tunnel traffic which has improved it somewhat but I still get packet loss every once in a while. I am wondering if it could be something to do with the way that the fortigate processes ip traffic and that it runs out of resources if there is heavy traffic while end users are browsing the net. I did notice the same thing with Sonicwall firewalls so that is why I choose the Fortigate product line in the end.
    UkWizard
    New Member
    May 17, 2005
    But it could be the isp connection at the other end, rather than your end, which would make sense, as the other link is fine. What happens when there is packet loss ? does the vpn drop ? You could sniff the external interface for packets destined to the remote firewall during the packet loss, to see whether your end is not getting a response back. (see cli diag sniff command for usage) Also what happens if you disable the VPN policy that works, and does the other one then work properly ?. One last question, is the vpn that works all the time located above the other encrypt rule in the policies ?
    mikevan
    mikevanAuthor
    New Member
    May 17, 2005
    The config is such as this. I have one Fortinet 60 with 2 tunnels terminating to the same gateway. I have configured it this way for security reasons. On one Fortigate 60 The internal interface is subnet 10.10.10.0/24 with an encrypted tunnel to the central gateway. The DMZ interface is subnet 192.168.10.0/24 with an encrypted tunnel to the same central gateway as above. Both interfaces do not have protection profiles applied to them. When I ping both tunnels at the same time, one will get a request timed out where the other one does not. Both tunnels will get a request timed out (about 1 in a 100 pings) but not at the same time. The VPN does not drop. I think that answers your questions. Thanks for your help.
    UkWizard
    New Member
    May 17, 2005
    oh hang on, when you say two vpns terminating, are you meaning one vpn connection or two to different remote end firewalls (i presumed the latter).
    mikevan
    mikevanAuthor
    New Member
    May 24, 2005
    The config is such as this. I have one Fortinet 60 with 2 tunnels terminating to the same gateway. I have configured it this way for security reasons. On one Fortigate 60 The internal interface is subnet 10.10.10.0/24 with an encrypted tunnel to the central gateway. The DMZ interface is subnet 192.168.10.0/24 with an encrypted tunnel to the same central gateway as above. Both interfaces do not have protection profiles applied to them. When I ping both tunnels at the same time, one will get a request timed out where the other one does not. Both tunnels will get a request timed out (about 1 in a 100 pings) but not at the same time. The VPN does not drop. I think that answers your questions. Thanks for your help.
    Contributor III
    May 25, 2005
    I am also having a pretty similiar problem. VPN clients connected through Forticlient would hang after sometime so we have to switch to ssh for file transfers. Why does this happen, really?
    UkWizard
    New Member
    May 25, 2005
    Sorry for the delay, been away working. Try the following, the more you try together the more chance you have to get it working; use local id for each end of the tunnel, and only allow that id to connect use aggressive mode for the vpn settings use xauth Start from the top, until you have all three of these set, and it might fix your problem. As i suspect the vpn traffic is getting confused with which vpn to speak to at the other end. (seen a similar problem with multiple dialup entries) Otherwise, just use one tunnel for both if you can. Also make sure you dont have NAT enabled on any vpn policies.
    mikevan
    mikevanAuthor
    New Member
    June 14, 2005
    Thanks for you assistance in this matter. I have reconfigured it so that both subnets go through the same tunnel. I am still experiencing problems with packets being lost. If you ask me, I think there is a bug in the firmware. Mike.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!