Hi,
this FG60F with 7.4.5 (before 7.4.4 and same problems) has lots of problems with SD WAN.
Today I was there to ceck internet access and SD Wan config but I cant solve the problem. The SD WAN is strange, like at least 2-3 times a week and than for some hours one of the WANs has 30-80% package loss. Also than navigating behind the FG you notice the problem when you are using WAN x at this moment.
At the same time that the FG showed 70% package loss, I connected my laptop behind the router and checking with pings and internet speed test the line for >20min and NO problem at all. Again connecting to the FG I get package loss. I changed even the cable to be sure.
The SD Wan config is simple, one implicit rule sessions 50-50 and Performance SLA to ping Cloudflare 1.1.1.1 and 5-5-10-500-5-5 all activated.
What can be the reason of these package loss showing in the FG? Also I have fortiddns over WAN1 and when it shows package loss, I have problems connecting from outsider to the FG.
Thanks!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Speed/duplex settings?
Hi,
i checked and updated realistic data from the ISP.
Again today we get package loss with the new line and again behind the router everything is fine.
I dont get it, why does the FG show package loss if ther shouldnt be any. Thats a big problem, SD WAN in this customer is working really bad
Thanks
What do you mean "realists data"? What is package loss?
Hi,
it is just not working fine. The FG starts with showing package loss in SD WAN Performance Status (from 10-75%) which is not correct because if I connect to the router and start diagnosing I can ping and whatever.
Than users get problems, especially users on the wifi since I thing that if the AP is on the package loss line, the user switches to another AP and than everything just gets worse.
Also I see package loss like 50% on WAN2 and we have like 3 VPNs over WAN2 and they are working, traffic is passing (Camaras).
Yesterday I changed to all traffic on WAN1 with SD rule and no package loss on both WANs (the other one is used for VPNs).
Thanks
Created on 09-30-2024 12:48 AM
Hi,
this morning I have another FG60F with 7.0.15 with problems with 2 WANs in SD WAN. Both show package loss.
This is getting really serious, I am sure that the internet access is fine.
Thanks
Try setting the healtcheck / sla protocol to "DNS" instead of ping.
We had some issues in the past with ping only to public DNS destinations (I think it was provider related).
It's maybe also a good idea to add a second server as target.
I have 2 sites now, I changed from AWS and Office.com to 2 spanish DNS servers and it is the same. Pinging both of them directly from the FW I dont get package loss, but like 300ms and more.
Hi,
is there a known issue about SD WAN in 7.4.5?
I have big problems with this config. I changed SD WAN Rule so that ALL are using interface WAN1 just to have some time and thinking that it cant fail. I suppose that without SLA it should just work with this route but yesterday again I had both WANs down. One of them is using VPNs and access to cameras and VPN and cameras were UP all the time.
First of all, using on top the SD WAN rule for WAN1 the SLA Performance should not affect any downside of the WAN, correct?
What can be the cause and problem that like 2-3 times a week both internet accesses are gone for the FG but I know for sure that they are working fine.
My SLA performance rule is normal to 1.1.1.1 and 1.0.0.1 ping with standard values.
Thanks!
ask your provider what MTU Setting you should use and configure as told.
Also consider a downgrade to 7.2.9/7.2.10 if this is a productive environment: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-Release-for-FortiOS/ta-p/22717...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.