Topology
Spoke ---ipsec--- SDWAN HUB ---ipsec--- DC (non Fortigate)
Site A(Spoke) and Site B(Spoke) follow the same topology.
However on Site A, when I do a ping sweep to a resource on DC I see a 3-4% packet loss, when I do a ping sweep from Site A to SDWAN Hub there is no packet loss. There are no packet loss monitored on the performance SLAs as well.
I mirror the same test for Site B and other sites and dont have this issue and they are all using the same template configurations.
Tried to play with NPU, MTU, MSS as per several guides but did not resolve the issue.
env: 7.2.8
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello.
I will answer to the question: how to troubleshoot IPsec packet loss on a FortiGate:
Could be a configuration issue specific to Site A.
User | Count |
---|---|
2579 | |
1376 | |
796 | |
657 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.