Hi All,
Customer is running non forti APs with a Wireless Controller located over an IPSec VPN from my Fortigate to their ASA.
AP's are losing their connection to the controller, and the customer is confident the Fortigate isn't sending on CAPWAP traffic.
I thought this might be an MTU issue, with ASA side set to 1500, Fortigate was set to 1420 so I've increased it to 1500 but issue is still ongoing,
Any ideas, or debugs I can run to help determine the cause?
Thanks,
Solved! Go to Solution.
Thanks hbac, found some stale sessions and changed the config to stop this which has worked.
Thanks
For VPN setups over internet, most ISP will not allow higher values of MTU (more than 1500). What you can do is lower the MTU for the traffic that is going to be encapsulated in the VPN to avoid fragmentations or possible drops. Doing this changes directly on the AP/WLC could be a safer approach but also in FGT you can tune the MTU values for the VPN traffic.
Customer already has lowered the MTU, so this shouldn't be an issue. They believe the Fortigate is dropping DSTL packets.
Any reason for this?
Thanks for the reply Emirjon.
so change the MTU value on the AP's and WLC to say 1400, and leave the IPSec VPN Interface at 1500?
Hi @RichyRoss,
You can run packet captures and debug flows to make sure the traffic is not being blocked. Please refer to https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...
Regards,
Thanks hbac, found some stale sessions and changed the config to stop this which has worked.
Thanks
Hi @RichyRoss,
Could you please be more specific on what changes you have performed to get this resolved. I am having a similar issue with a customer, running CAPWAP tunnels over sd-wan IPSEC tunnels. Issues arise when traffic is being steered.
Thanks
A
Hey Andrei,
If memory serves I set the MTU to 1500 on the IPSEC interface, and also enabled MTU discovery globally, which I think solved it.
Thanks
User | Count |
---|---|
1922 | |
1144 | |
769 | |
447 | |
277 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.