Description | This article describes that a limitation of SSL VPN load balancing exists in FortiGate-6K/7K Chassis. |
Scope | FortiGate-6K/7K Chassis. |
Solution |
SSLVPN support load balance is now supported in most of the latest firmware of FortiGate-6K/7K Chassis:
In certain situations, load balancing cannot be done. For example, in a situation where the DMZ/internal server is a source initiating connection to the destination as an SSL VPN host.
This situation mostly happens in the VoIP environment when the call server receives a call request and forwards it to the target SSL VPN host.
When the chassis's FIM/MBD receives this type of request, then it will forward to a blade by following the load balancing algorithm, and end the traffic may reach a worker FPM/FPC which does not have the SSL VPN setup to the SSL VPN host and caused the connection dropped.
Solution:
Disable load balancing for SSL VPN:
config load-balance setting set sslvpn-load-balance disable end
Create flow rule to master blade:
config load-balance flow-rule |