Description |
This article describes why the health check is showing the specific SD-WAN member down even if the destination is reachable to the member interface. |
Scope |
FortiGate. |
Solution |
Configured are two IPsec interfaces in the SD-WAN but IPSEC-2 is showing down.
When testing reachability from FortiGate, both interfaces can reach the destination without any issues.
Running a packet capture shows there is a reply on IPSEC-1.
However, in IPSEC-2 the reply packets are not returning to the correct interface.
SD-WAN health check detects the interface as ‘DOWN’ if the traffic is not returning to the correct interface even if the traffic is successful.
Once the traffic is returned to the correct interface, the SD-WAN health check will now detect the interface as UP.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.