Hello
I am experiencing a strange issue with Fortigate 600C firewall. Time to time whole network is disconnect and reconnect within 3-5 secs. There is no any ping drops. But all the user sessions are dropping. (eg. Internet, SAP users, IPPhones, etc..)
The unit was on FortiOS 5.2.5 and I have upgraded it to 5.2.11 (5.2.5 -> 5.2.7 -> 5.2.9 -> 5.2.11) also changed the hardware too. (Tried different FG 600C unit) But still unable to find the cause to this issue. Please assist me to identify this issue.
Thank you
Damitha
Hi Damitha,
There can be many reasons why users/services experiencing dropouts.
1.During the outage, can you access other networks that are directly connected to the Fortigate, apart from the Internet link?
2.Do you see the same issue if you bypass the Fortigate?
3.The affected services, are they routed via a IPSec VPN ---> Datacenter ---> Internet or is it a direct link to the internet?
Best option will be to raise a support ticket with Fortinet TAC @ https://support.fortinet.com
Kind regards,
Rukshan
Do you have logging enabled? Can you reviews logs at the time of the event(s)?
Since you changd hardware, changed code, what else do you have in the network path?
Also what do you mean exactly by
There is no any ping drops. But all the user sessions are dropping. (eg. Internet, SAP users, IPPhones, etc..)
If you have applications failing, run diagsnotsic or logs against the application and look for similarities ( SIP registeration timeouts for example....)
PCNSE
NSE
StrongSwan
Hi Damitha
Do you have any solution for your issue?
We have the issue that from timet to time, the SAP connections are reseted with an WSAECONNRESET error on the client. I dont know if other connection are allso affected, but SAP is realy picky with connection disruptions.
Hi
having only issue with traffic which is passing through fortigate?
or issue in the same subnet ? ( eg: connection lost between 192.168.1.1 to 192.168.1.2)
did you make any change in the global timer ?
check it
config system global
show full-config
Regards
Mahesh
Hi
The issue arise with the Network Segmentation, now the clients have to traverse the Firewall (Traffic is allowed) to get to the SAP Server. Also the issue only happens from time to time, sometimes once a day and sometimes once a week.
What do you mean with global timer? The session timeout? For the SAP traffic this is set to 8 h.
Best regards
Hi
the Global Timer settings are as folow
set tcp-halfclose-timer 120 set tcp-halfopen-timer 10 set tcp-option enable set tcp-timewait-timer 1 set udp-idle-timer 180
I think this are the default values
I just take over the case so I dont know if there were did some changes erlier.
I've attached the Output of the configuration.
Thanks and best regards
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 704 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.