FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
totsuka
Staff
Staff
Article Id 424449
Description

This article describes how to troubleshoot and use a workaround or fix for scenarios where IPsec VPN traffic unexpectedly stops.

Scope NP6, NP6xlite, SOC4 model.
Solution

Troubleshooting:

 

Execute the following CLI command several times and confirm that the output continues to show '00000000'.

diagnose npu np6xlite register 0 | grep engine_status
engine_status =00000000 [16:23]

 

Cause:

 

If the value continues to show '00000000', the IPsec Engine will hang due to NP buffer limitation.

 

  1. Workaround:

 

Disable NPU offloading.

 

config firewall policy
    edit <policy_name>
        set auto-asic-offload disable
end

  1. Fix:

 

Upgrade to one of the following versions for a fix:

  • 7.4.10.
  • 7.6.5.
  • 8.0.0.
Contributors