Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

FGT 40F issue with IPsec

Hi FGT admins

We have FGT 40F with FOS 7.4.7. It has s2s IPsec tunnel with HQ FGT.

We noticed from time to time (approximately 10 times per hour) the there is no traffic going through the tunnel anymore for about a minute or two, then it back again to normal operation, while we see the tunnel is always up (both phase 1 & 2).

When we replace the 40F with a 100F we notice all works fine with no interruption.

The problem started about 2 weeks ago, even though there were no changes to the firewall (no firmware upgrade, no configuration changes).

Any helpful info would be appreciated.

AEK
AEK
2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

I would probably start looking for something in the log first. Then if nothing is there, I would try running continuous pinging over the tunnel if it would stop getting replies during those periods. Then eventual need to capture the moment and run flow debug on both sides to see what's going on at that time on which end.

Toshi

AEK

Thanks Toshi, I'll do that.

I'll also try disable phase 1 npu offload and see if it helps.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors