Description |
This article describes the case when sending traffic over an IPsec tunnel, debug flow displays the following error:
id=65308 trace_id=15 func=resolve_ip_tuple_fast line=5930 msg="Find an existing session, id-00090049, reply direction" |
Scope | Any FortiOS on VM. |
Solution |
So, the traffic is being offloaded by the CPU. The debug flow message indicating 'offloading-check failed, reason_code=2' for IPsec traffic means that the offloading of the IPsec Security Association (SA) failed due to the absence of the Network Processing Unit (NPU). This is expected behavior for VM-based FortiGates, which do not have NPUs and rely on CPU processing for IPsec encryption and decryption.
Reason Code 2: This specific code signifies that the IPsec offloading failed because the device does not have an NPU. This is typical for VM-based FortiGates. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.