Hi FGT admins
We have FGT 40F with FOS 7.4.7. It has s2s IPsec tunnel with HQ FGT.
We noticed from time to time (approximately 10 times per hour) the there is no traffic going through the tunnel anymore for about a minute or two, then it back again to normal operation, while we see the tunnel is always up (both phase 1 & 2).
When we replace the 40F with a 100F we notice all works fine with no interruption.
The problem started about 2 weeks ago, even though there were no changes to the firewall (no firmware upgrade, no configuration changes).
Any helpful info would be appreciated.
I would probably start looking for something in the log first. Then if nothing is there, I would try running continuous pinging over the tunnel if it would stop getting replies during those periods. Then eventual need to capture the moment and run flow debug on both sides to see what's going on at that time on which end.
Toshi
Thanks Toshi, I'll do that.
I'll also try disable phase 1 npu offload and see if it helps.
User | Count |
---|---|
2400 | |
1289 | |
778 | |
521 | |
454 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.