We have Fortigate 100D. IPsec site to site tunnels were working fine. but suddenly ipsec tunnels stop passing traffic and ipsec client users were also unable to connect or getting disconnected after 1 minute. I checked the logs & reports > Event Logs > VPN; there i noted some error in vpn phases i.e. dpd_failure, esp_error etc.
Then without any changes in configuration i restarted fortigate, and every thing was fine then
But i want to find the root cause for this to avoid downtime in future cause my company can't bear downtime.
Please find the attached image for error details. Please find out what was the root cause for this problem.
Regards,
Asad Khan
---------------------------
FCNSA, CCNA, MCSE 2012
asad khan
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
HI Khan
Have you resolved this fortigate vpn tunnel issue?..
Hi ,
This could be a bandwidth issue.
Dead Peer Detection (DPD) always check the availability of Remote peer and if find any problem with the accessibility it will bring down the tunnel once the threshold value reaches.
Check the latency to any of the internet destinations while you face the problem. There is no other reasons for the outage especially you have mentioned that, during the time IPSec Client users also had the same problem. I would suggest to keep your eye on the band width utilization of the link which you are using for S2S and C2S IPSec VPNs.
Thanks
Nihas
Yes................Restarting the Fortigate is a solution only................
And regarding that esp_error, Fortinet TAC is saying that it is a known bug.
But After restarting unit, it didn't happened again, though i can still see the errors notification in the logs a about every day.
asad khan
Hi Nihas,
You are right. But at the time of issue, i checked the bandwidth & ISP (internet) line first. It was ok. For internet line there was no drops. I can surely say that Bandwidth was ok at the time of issue.
There are many things so are not sure about some specific one. It is the Fortinet TAC who should point out the root cause.
asad khan
Yea.. I understand. :)
I too had faced the similar kind of issues with my VPN's.
It was all about either the internet link problem or the remote peer IP reachability problem.
While restarting the box , all sessions will close and the band width pool becomes free. So the tunnel wouldn't have any problem to re-establish the connectivity. That's the basic logic behind on this specific issue.. !
Let's wait to hear the expert opinion from TAC guys.
Cheers..
Nihas
I was also lead to believe it could be an encryption problem, like the encryption was too high which slowed things down under a large amount of throughput and caused these problems... maybe someone can confirm
We have 2x100D in HA(fw v5.0.9) with "low" throuput (10-5 Mbit/s) and this bug occured after 489 days of uptime.
Our support admin denied the root of the problem with 100d at first. After reboot ihe ip-sec far-ends immediately connected perfectly.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1643 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.