Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dave1
New Contributor

IPSEC Packetloss

Topology

Spoke ---ipsec--- SDWAN HUB ---ipsec--- DC (non Fortigate)

Site A(Spoke) and Site B(Spoke) follow the same topology.

However on Site A, when I do a ping sweep to a resource on DC I see a 3-4% packet loss, when I do a ping sweep from Site A to SDWAN Hub there is no packet loss. There are no packet loss monitored on the performance SLAs as well.

 

I mirror the same test for Site B and other sites and dont have this issue and they are all using the same template configurations.

 

Tried to play with NPU, MTU, MSS as per several guides but did not resolve the issue.

 

env: 7.2.8

 

3 REPLIES 3
Stephen_G
Moderator
Moderator

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen - Fortinet Community Team
Anthony_E
Community Manager
Community Manager

Hello.

 

I will answer to the question: how to troubleshoot IPsec packet loss on a FortiGate:

  1. Check for packet loss on the SDWAN health-check:  Run the command: 'diagnose sys sdwan health-check'  and look for packet loss percentages for the VPN connections.
  2. Monitor Phase1 creation time:  Use the command: 'diagnose vpn ike gateway list | grep "name:\|created'  and check the time taken for Phase1 to be created.
  3. Verify routing table entries:  Execute: 'get router info routing-table details <destination-IP> and ensure that routes are correctly installed for the VPN tunnels. 
  4. Debug the IKE process:  Run: 'diagnose debug application ike -1'  and enable debug: 'diagnose debug enable'.  Filter the output for the specific network causing issues.
Anthony-Fortinet Community Team.
SullivanCrew
New Contributor

Could be a configuration issue specific to Site A.

Spoiler
Site A's connection to the DC, despite following the same configuration as other sites. Since adjusting NPU, MTU, and MSS didn’t help, you could try checking for any path-specific issues, such as routing anomalies or asymmetric routing, which may be causing packet loss. Monitoring the traffic with additional diagnostic tools might provide more insight. I had a tight deadline for my economics assignment and needed urgent help. I didn’t have a huge budget, so I was sceptical about using an online writing service. That’s when I found UKWritings where I can buy a cheap assignment, which you can check out here https://ukwritings.com/cheap-assignment and The price was reasonable, and the quality exceeded my expectations. The expert followed my instructions, used relevant sources, and delivered a paper that met all academic requirements. I submitted it on time and got a great grade! If you’re looking for affordable yet high-quality assignment assistance, this service is definitely worth considering.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors