| Description | This article explains why replay detection errors appear in IPsec logs when an SD-WAN rule uses the Lowest cost (SLA) strategy with Load balancing enabled. |
| Scope |
FortiGate with:
|
| Solution |
In this configuration, when multiple IPsec members meet the SLA target and have the same cost, Load balancing distributes sessions across all eligible tunnels.
Each tunnel maintains a separate Security Association (SA) with independent ESP sequence numbers. Replay detection is enabled by default under the phase2 configuration.
date=2025-10-06 time=15:04:34 id=7558093854767841317 type="event" subtype="vpn" level="critical" action="error" msg="IPsec ESP error" logdesc="IPsec ESP" remip=1.1.1.1 locip=2.2.2.2 vpntunnel="HUB1" error_num="Invalid ESP packet detected (replayed packet)." Resolution:
config system sdwan
FGT (phase2-interface) # edit HUB1 FGT (HUB1) # show
Key point: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.