Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ctyctyctctcty
New Contributor

ADVPN Tunnel Packet Loss Issues

Hey everyone,

I'm working with a FortiGate 40F setup, using an ADVPN with IPsec to connect 1 hub and 2 spokes. For routing internal traffic through the ADVPN tunnel, I'm relying on SD-WAN rules and SLA checks.

Just to add some context, I'm using my ISP’s WAN interface as the ADVPN tunnel interface, and it’s set up to get an IPv6 address from FortiGuard. That part is working smoothly—no issues with IPv6 or IPv4 internet connectivity at all.

The problem:I’m experiencing a consistent packet loss between 30% and 70% on the ADVPN tunnel interfaces, as indicated by the SD-WAN SLA ping checks. This packet loss is specific to the ADVPN tunnel interfaces, while other connections seem unaffected.

What I have tried out:
MTU adjustments (to 1380) ~~not working
Enabled FEC on one of the device ~~not working

Are there anything else i should try? I’d really appreciate any insights or advice!
image.png




1 REPLY 1
Umer221
Staff
Staff

Hello @ctyctyctctcty 

Try running a sniffer on the source and destination side to see where the loss is occurring.

dia sniffer packet "host x.x.x.x and icmp" 4 0 l

 

Try using the above command, where x.x.x.x is the source IP address that you have on performance SLA. Run the sniffer command on the source as well as on destination FortiGate if both sides are FortiGate.
Check if one side is sending and other side is not receiving or other side receives but the returning traffic is not reaching the original source?

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors