Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
chokyarsyi
New Contributor

IPSec VPN error "Dropped by template device"

Hello guys,

 

We have 5 branches and use IPsecVPN to head office, but We are having a problem with 3 branches of our ipsec. There is a message in the trace we have never heard of and we don't find any documentation about it.

 

 id=20085 trace_id=23 func=print_pkt_detail line=5501 msg="vd-root:0 received a packet(proto=1, 10.1.12.32:8->10.3.1.254:2048) from port8. type=8, code=0, id=8, seq=38071." id=20085 trace_id=23 func=resolve_ip_tuple_fast line=5581 msg="Find an existing session, id-1b1e4875, original direction" id=20085 trace_id=23 func=ipv4_fast_cb line=53 msg="enter fast path" id=20085 trace_id=23 func=ipsecdev_hard_start_xmit line=753 msg="Dropped by template device VPN_Branch."

 

Is someone knows the meaning of this msg : Dropped by templace device ? What can cause it ?

1 REPLY 1
Chandra_FTNT
Staff
Staff

Hi,

 

Please verify if the net-device is enabled on the IPsec tunnel, there is behavior change in the firmware, please check below KB:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-set-net-device-new-route-based-IPsec-logic...

 

Let us know if the issue persists.

 

Regards,

Chandra

Labels
Top Kudoed Authors