Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FrankCQI
New Contributor

Loosing internet connection

Here is our setup. Fortigate 60B. Static IP from ISP connected to WAN1 port. We randomly loose connection to internet. ISP modem and router are up and running. Fortigate is up and running, it just doesn' t seem to link our lan with the wan port to acces internet. Any idea what might be causing this? It seem to appen randomly but always around the same time 4-5 AM. Can it be related to fortigate updating itself? Any idea?
Frank
Frank
5 REPLIES 5
Matthijs
New Contributor II

Maybe some script from your internal to internet that causes the fortiwall to go into conserve mode? How do you resolve it? If you don' t power down the unit you could see it in the gui. You can be notified about it: http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD31969&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=24738384&stateId=0%200%2024736499 Also, set the update schedule of the FortiGate to update once a day at 01:00 am to see if this helps ;-) Connecting a console cable to the FortiGate and leave this open to see if there are any errors flowing can also help indicating what is the problem.
FrankCQI
New Contributor

We resolve it by rebooting the fortigate. I noticed the following log messages when it appen: 73 2011-10-11 05:52:39 critical Ping peer: xxx.xxx.xxx.xxx is down Then our IP sec tunnel drop and internet is no more available until we restart.
Frank
Frank
ede_pfau
SuperUser
SuperUser

Then check your WAN interface setup in System>Network>Interface, and look for the section starting with " Detect Interface Status for Gateway Load Balancing" . You have enabled it and chosen a peer server on the other end of the ISP line that is unavailable once a day at around 5 am. You can either - choose a different, known stable server on the internet (like a NTP source) - configure a second ping target (append second IP/FQDN with a space) - disable the Detect Server setup as you only have one WAN line Basically, the Detect Server config helps to quickly delete the default route in case the internet has become unavailable. Otherwise, only a ' Link down' event would trigger this, and that will happen only if you pull the cable from the WAN port. OTOH it doesn' t hurt you much if your FGT does not detect the connectivity loss - traffic will be sent out WAN port but never get replied. Best practice is to enable Detect Server as then the FGT sends out an SNMP trap to your NMS station and you get alerted. Just be careful that you choose a reliable ping target on the ISP' s internal net or close by.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
FrankCQI

Thanks, I will give it a try.
Frank
Frank
giovinco_06
New Contributor

Hi FrankCQI, I just want to share that, my fortigate unit 110 C , also got the same problem like u. It will not respond randomly in the morning around 1.00 AM - 5.00 AM. Do you already solve the problem ??
FGC-110C v4.0 MR2 Patch 9 -aboe-
FGC-110C v4.0 MR2 Patch 9 -aboe-
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors