Hello Experts,
I have an issue about site-to-site SD-WAN. Here is the situation.
There are 2 ipsec tunnels between 2 Fortigates.
One tunnel (called as X) is a simple ipsec tunnel.
The other (called as Y) is a ipsec aggregation tunnel which has 3 ipsec tunnels (Y1, Y2, Y3)
FG1 -- X ------- Network_A ------- X -- FG2
-- Y - Y1 -- Network_B -- Y1 - Y --
- Y2 -- Network_C -- Y2 -
= Y3 -- Network_D -- Y3 -
(I hope you understand the above configuration.)
When all Network_A,B,C,D belong to normal network, everything is ok.
(Both X and Y are seen as green in SD-WAN performance SLA).
However, when Network_B,C,D belongs to slow network such as satellite,
Only X is OK (alive). Y is not alive as SD-WAN, although all ipsec tunnels (Y1, Y2, Y3)
and aggregated Y are established as vpn tunnel.
(Y is seen as red in SD-WAN performance SLA, however all are seen as green in VPN page.)
In this case of slow network, ping response time is about 600ms.
At normal network here, the response time is less than 150ms.
What and how should I do so that both X and Y are active at slow network?
Thanks in advance,
The symptoms sound like MTU changes across the WAN not being handled correctly. Try clamping MSS on an edge device that you control at one of the problematic sites. If that fixes the issue, you now know what to start troubleshooting.
Dear pukalmu3,
Thanks for your comments. MTUs in all cases are 1500.
Only difference would be latency (delay) between normal case and slow case, I think.
I am now looking for some related parameters.
Still waiting experts comments.
Thanks in advance.
Hi,
You can make a few adjustments to make this work. First, you can consider increasing the probe timeout setting in the sla configuration to accommodate the higher latency for the slow network. Second, adjust the SLA thresholds for latency, jitter, and packet loss for the slow tunnel connections. Once you make these changes, monitor the SD-WAN perf status to verify if the agg tunnel becomes active.
Thanks,
Dear Atul,
Thanks for your key comments.
I will try. After I get something, I will get back here.
Best regards,
User | Count |
---|---|
2625 | |
1400 | |
810 | |
672 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.