Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
devrajga
New Contributor

Tunnel flapping, frequent disconnects and reconnects, between a FortiGate 7.2.9 and 7.4.7 device

Tunnel flapping, or frequent disconnects and reconnects, between a FortiGate 7.2.9 (HUB) and 7.4.7 (Spoke) device in an ADVPN setup.

Following this are observed.

In IPsec VPN logs DPD failure errors is showing

IPSec tunnel disconnect and reconnect frequently.

BGP neighbor renegotiation.

observed packet loss 16 % frequently, unable to figure it out reason of packet loss in the tunnels not on public interfaces.

2 REPLIES 2
syordanov
Staff
Staff


Hello devrajga ,

Does the problem persist with one particular spoke or you have this problem with the rest of the spokes?
Is the problem is only for one spoke, check for DoS policy and anothing which could be different on this location.
Try to disable the offloading on this spoke:

 


config vpn ipsec phase1-interface
edit phase-1-name
set npu-offload enable
end

 

- One the IPSec is offloaded, try to run the IKE debug bellow :

 


diagnose vpn ike log filter name name_of_affected_IPSEC
diagnose debug app ike -1
diagnose debug console timestamp enable
diagnose debug enable


Best regards,

Fortinet

.
devrajga

Hello Syordanov,

Thanks for your response.

This issue involves multiple spokes with models like 61E, 81E, 81F, and 201E.

When I checked the IKE logs, the DPD failed multiple times.

I have observed high packet loss in tunnel interfaces between 16% to 22% frequently, but not on public IP interfaces between HUB and Spoke, checking these packet losses observed through SDWAN performance SLA.

Note:- I have also removed the performance SLA (health-check) from the SDWAN rule (config service). 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors