Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nicholasscheetz
New Contributor

Pass Through Port Meraki & Firepower Dropped Traffic

We were working w/ Lumen on getting Fortinet SD Wan setup. We currently have Meraki and Firepower FIrewalls sitting behind a pass through port on versas, but when switching to the exact same setup on Fortinet, a lot of traffic was dropping. Mainly UDP because thats what meraki was complaining about. Is there something the Lumen tech was missing that would cause this to happen? 

 

 

 

4 REPLIES 4
Jean-Philippe_P
Moderator
Moderator

Hello nicholasscheetz, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello nicholasscheetz,

 

I found this solution, can you tell me if it helps you?

 

To address the issue of dropped UDP traffic when switching to Fortinet SD-WAN, consider the following steps:

 

  1. Firewall Policy Configuration: Ensure that the firewall policies on the Fortinet device are correctly configured to allow the necessary UDP traffic. Check for any specific rules that might be blocking or restricting UDP packets.

  2. UDP Session Timeout: Verify the UDP session timeout settings on the Fortinet device. If the timeout is too short, it might cause sessions to drop prematurely.

  3. NAT Configuration: Check the NAT configuration to ensure that it is correctly translating the UDP traffic. Misconfigured NAT settings can lead to dropped packets.

  4. SD-WAN Rules: Review the SD-WAN rules to ensure that they are correctly prioritizing and routing UDP traffic. Incorrect rules might cause traffic to be routed through less optimal paths, leading to drops.

  5. Packet Fragmentation: Investigate if packet fragmentation is occurring, which can lead to dropped packets. Ensure that the MTU settings are correctly configured to prevent fragmentation.

  6. Offloading Settings: If hardware offloading is enabled, consider disabling it temporarily to see if it affects the traffic flow. Offloading can sometimes cause issues with certain types of traffic.

  7. Diagnostics and Logs: Use FortiGate's diagnostic tools and logs to identify where the traffic is being dropped. This can provide insights into whether the issue is with the Fortinet device or elsewhere in the network.
Jean-Philippe - Fortinet Community Team
nicholasscheetz

Thank you! I'll go over these settings and let you know

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors