| Description | This article describes how to fix the issue (SYN, ECE, CWR) packets received from the BGP peer over the IPsec tunnel. |
| Scope | FortiGate. |
| Solution |
The BGP may receive the following packet from the BGP peer while the remote peer is through an IPsec tunnel:
Internet Protocol Version 4, Src: 192.168.10.1, Dst: 172.16.1.12
This could be an NPU issue, so disabling NPU can be an option:
config vpn ipsec phase1 edit phase-1-name set npu-offload disable end |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.