- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Getting Packet Drop issue on IPsec VPN Tunnel, after upgrade the FortiOS v7.4.3
Dear All.
We've encountered packet drop issues on the IPsec VPN tunnel between our FortiGate and AWS after upgrade FortiOS v7.4.3. Disabling the 'NPU Offload' has alleviated some of the packet loss problems, but we're still experiencing frequent packet loss, averaging around 5-6%.
In order to address this persisting issue, could you please provide some solutions or recommendations for resolving it?
With regards,
Bhaskar Rao
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @bhaskarrao,
Did you try disabling 'replay detection'? There is a known issue with bug ID 1003830. Please refer to https://docs.fortinet.com/document/fortigate/7.4.3/fortios-release-notes/236526/known-issues
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We did disable that option in phase-2, but unfortunately, the issue persists unchanged. We haven't seen any improvement despite our efforts.
is there any other workaround to fix this issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you have multiple tunnels going to AWS or just one? You can take packet captures on both sides to see where the packets are lost.
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just adding that this still has not been fixed in 7.4.4.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
What model is your FGT device?
Is the tunnel between physical FGT and FGT located in AWS?
Any logs being generated on the end devices such as ESP packet errors, HMAC validation errors that coincide with the drops you experience?
If the device is a F series FGT disabling offloading and replay detection should resolve the issue.
Created on ‎05-16-2024 08:30 PM Edited on ‎05-16-2024 08:50 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
The FGT model is 500E and IPsec VPN tunnel between FGT and AWS.
We tried disabling offloading and replay detection but issue remain same.
Please find the log file for your reference.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
The FGT model is 500E and IPsec VPN tunnel between FGT and AWS. We have tried disabling offloading and replay detection but issue remain same.
Please find the log for your reference.
