Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Anand_Narayana
Contributor

TCP connection resets for a specific URL

Dear All, We are currently experiencing an issue with 2 of our fortinet 310B devices placed in 2 different locations. www.xyz.com is where all the users in our LAN uploads document files (size of max. 150KB) using an application which connects/uses port 80 & 443 for communication. No port or catagory based restriction for the LAN users configured in Fortinet. In the past couple of days, we have been experiencing problem that the connection to www.xyz.com resets intermittently. When we ran a wireshark packet capturing application, we saw " TCP Dup ACK" messages very often which confirms a communication resets occurred. Later when we routed www.xyz.com through our Cisco ASA/PIX in both the location, our problem got resolved. This problem occurs only when it was routing through fortinet. Would this solution resolves my issue? http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD30171&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=6874945&stateId=0 Fortigate-310B 3.00-b5469(MR7)

Anand

Anand
4 REPLIES 4
Anand_Narayana
Contributor

I tried increasing/decreasing the tcp session value but end up with no luck. Any ideas?

Anand

Anand
laf
New Contributor II

Tough one. What firmware are you using? Can you open a ticket to support guys? Did you have push updates enabled?

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
romanr
Valued Contributor

Hi, is there any protection profile enabled on this connection? A TCP reset might have been caused by the IPS engine -> Have you had a look through your IPS logs? Also have you tried running a flow debug on that session specifically? It might post a reason for this reset! diagnose debug flow filter saddr x.x.x.x (source address) diagnose debug flow filter daddr x.x.x.x (dest address) diagnose debug enable diag debug flow trace start 10000 (number of packets) Maybe this will show up an answer! regards, Roman
simonorch
Contributor

Just a thought but take a look at the NP2 statistics and see if there are any errors. You can also disable the NP2 and see if there' s a difference. In the earlier 310B' s there was a problem with the revision 1 version of the NP2 processors.

NSE8
Fortinet Expert partner - Norway

NSE8Fortinet Expert partner - Norway
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors