Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
viskanmai
New Contributor

IPSec issues on 7.4.9

Hi All,

Has anyone noticed issues with IPSec site to site tunnels on 7.4.9?

We have one vendor who has been working fine before we upgraded a couple weeks back to version 7.4.9 in our Azure FG. Oddly enough our one firewall in HQ location which still is on 7.2.12 works fine.

When comparing the 2 tunnels from Azure FG and HQ FG doing pings to the vendor I noticed the HQ doesn't lose pings at all. Whereas the one in Azure will intermittently lose the pings and then come back on its own.

VPN settings for both FGs are the same along with vendor side.

Has anyone run into this so far? Any workarounds?

Happy Holidays All!

1 REPLY 1
kaman
Staff
Staff

Hi viskanmai,

If IPsec is being used on a public cloud environment (Azure, AWS) check the DOS policy and anomaly log, as slow throughput can be caused by UDP 4500/500 drops. Change the threshold value or disable the anomaly or the DOS policy to fix this.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Ensuring-IPsec-traffic-is-offloaded-for-im...


If IPsec is configured on a hardware device, please verify whether there are any IPsec NPU drops. If so, disable the NPU under the IPsec tunnel and then check the behaviour:

diagnose npu np6 dce 0
diagnose npu np6 dce 1


Test by disabling NPU offloading under IPsec phase1 tunnel and check the behaviour:

config vpn ipsec phase1-interface
edit <phase1-name>
set npu-offload disable
end


https://docs.fortinet.com/document/fortigate/7.6.4/hardware-acceleration/636026/disabling-np-offload...


If you have found a solution, please like and accept it to make it easily accessible to others.


Regards,
Aman

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors