Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ErwinLinker
New Contributor

Citrix provisioning high vdisk retries

Hi all,

 

I have a case with FortiNet but perhaps the community has some good idea's.

 

Recently we have migrated our routing(Dell switch) and firewall(Sophos UTM) to a FortiGate 600E cluster. Since we have migrated to the FortiGate we see on our Terminal Server vdisks a lot of retries (https://support.citrix.com/article/CTX222944).

We see this only on the networks that are routed and firewalled trough the FortiGate.

 

We have opend a case by the vendor (Citrix) and the told us, if the retries don't take place in the same network where the Citrix PVS machines are running, there is a network issue. 

 

I have tested to place a network back to the switch and then we don't see any retries on the terminal servers. The problems looks te be when the traffic goes trough the FortiGate.

 

Anybody got the same issue or has a idea where to look?

6 REPLIES 6
AlexC-FTNT
Staff
Staff

On the FortiGate, start with the very basic troubleshooting steps:

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...
Did you check the logs for any blocked traffic? Is the traffic passing the FortiGate unchanged? 


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
ErwinLinker
New Contributor

With support we did the basic troubelshouting, and everything looks okay.

It feels like some traffic is lost in de connection, Citrix PVS is running with UDP so its difficult to see that.

kaejoe
New Contributor

Did you find a solution for this problem?

ErwinLinker
New Contributor

Hi Kaejoe,

 

We found the problem. After some more troubelshouting support saw that the NP6 chip of the unit is dropping the traffic. The cache of the chip is getting full and then drops the traffic. There is no solution in the current unit we have, we have decided the change the netwerk from ou Citrix PVS machines to our terminal serverse.

kaejoe

Hi Erwin

 

Do you know the troubleshooting commands to see if we have the same issue? Model is also a 601E. You mean you change de pvs target device to the same subnet as the pvs servers?

ErwinLinker
New Contributor

Hi,

 

Sure. You need to look at the physical interfaces, for us it was the following commands

- diagnose hardware deviceinfo nic x1 

- diagnose hardware deviceinfo nic x2

- diagnose npu np6 dce-all 0

- get sys performance status 

 

In the logging we saw:

PDQ_OSW_EHP0 and/or PDQ_OSW_EHP2

That was the indication that there is dropped traffic.

 

Regards

 

Labels
Top Kudoed Authors