Tunnel flapping, or frequent disconnects and reconnects, between a FortiGate 7.2.9 (HUB) and 7.4.7 (Spoke) device in an ADVPN setup.
Following this are observed.
In IPsec VPN logs DPD failure errors is showing
IPSec tunnel disconnect and reconnect frequently.
BGP neighbor renegotiation.
observed packet loss 16 % frequently, unable to figure it out reason of packet loss in the tunnels not on public interfaces.
Hello devrajga ,
Does the problem persist with one particular spoke or you have this problem with the rest of the spokes?
Is the problem is only for one spoke, check for DoS policy and anothing which could be different on this location.
Try to disable the offloading on this spoke:
config vpn ipsec phase1-interface
edit phase-1-name
set npu-offload enable
end
- One the IPSec is offloaded, try to run the IKE debug bellow :
diagnose vpn ike log filter name name_of_affected_IPSEC
diagnose debug app ike -1
diagnose debug console timestamp enable
diagnose debug enable
Best regards,
Fortinet
Hello Syordanov,
Thanks for your response.
This issue involves multiple spokes with models like 61E, 81E, 81F, and 201E.
When I checked the IKE logs, the DPD failed multiple times.
I have observed high packet loss in tunnel interfaces between 16% to 22% frequently, but not on public IP interfaces between HUB and Spoke, checking these packet losses observed through SDWAN performance SLA.
Note:- I have also removed the performance SLA (health-check) from the SDWAN rule (config service).
User | Count |
---|---|
2549 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.