Description |
This article describes how to troubleshoot when packet loss is observed on an ADVPN tunnel. |
Scope |
FortiGate. |
Solution |
Step 1: Identify the Source and Destination locations. Both Source and Destination Behind Spokes (ADVPN not configured for shortcuts):
Both Source and Destination Behind Spokes (ADVPN configured for shortcuts): If a shortcut is created:
If no shortcut is created:
Either Source or Destination Behind Hub:
Step 2: Collect and Analyze Routing Information, Packet Sniffer Data, and Debug Logs.
get router info routing-table details x.x.x.x get router info routing-table details y.y.y.y
diagnose sniffer packet any 'host x.x.x.x and host y.y.y.y' 4 0 l
diag debug flow filter addr x.x.x.x diag deb flow show iprope en diag deb console timestamp en diag deb flow trace start 1000 diag deb en
Replace `x.x.x.x` with the source IP and `y.y.y.y` with the destination IP.
Step 3: Analyze Logs. Packet Sniffer Logs: Check if the logs show traffic exiting the correct IPSec tunnel (look for the 'tunnelname out' phrase) at the source FortiGate:
Check if the logs show traffic entering the correct IPSec tunnel (look for the 'tunnelname in' phrase) at the destination FortiGate:
Check if the logs show traffic entering the correct outbound interface at the destination FortiGate:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.