Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Asad_Khan
New Contributor

dpd_failure & esp_error - ipsec tunnels dropping all traffic pakcets

We have Fortigate 100D. IPsec site to site tunnels were working fine. but suddenly ipsec tunnels stop passing traffic and ipsec client users were also unable to connect or getting disconnected after 1 minute. I checked the logs & reports > Event Logs > VPN; there i noted some error in vpn phases i.e. dpd_failure, esp_error etc.

Then without any changes in configuration i restarted fortigate, and every thing was fine then

But i want to find the root cause for this to avoid downtime in future cause my company can't bear downtime.

Please find the attached image for error details. Please find out what was the root cause for this problem.

 

Regards,

Asad Khan

---------------------------

FCNSA, CCNA, MCSE 2012

 

asad khan

asad khan
7 REPLIES 7
ralphian08
New Contributor

HI Khan

 

Have you resolved this fortigate vpn tunnel issue?..

Nihas
New Contributor

Hi , 

This could be a bandwidth issue.

Dead Peer Detection (DPD) always check the availability of Remote peer and if find any problem with the accessibility it will bring down the tunnel once  the threshold value reaches.

 

Check the latency to any of the internet destinations while you face the problem. There is no other reasons for the outage especially you have mentioned that, during the time IPSec Client users also had the same problem. I would suggest to keep your eye on the band width utilization of the link which you are using for S2S and C2S IPSec VPNs.

 

Thanks

Nihas

Nihas [\b]
Nihas [\b]
Asad_Khan
New Contributor

Yes................Restarting the Fortigate is a solution only................

And regarding that esp_error, Fortinet TAC is saying that it is a known bug.

But After restarting unit, it didn't happened again, though i can still see the errors notification in the logs a about every day.

 

 

asad khan

asad khan
Asad_Khan
New Contributor

Hi Nihas,

You are right. But at the time of issue, i checked the bandwidth & ISP (internet) line first. It was ok. For internet line there was no drops. I can surely say that Bandwidth was ok at the time of issue.

There are many things so are not sure about some specific one. It is the Fortinet TAC who should point out the root cause.

 

 

asad khan

asad khan
Nihas
New Contributor

Yea.. I understand. :)

I too had faced the similar kind of issues with my VPN's.

It was all about either the internet link problem or the remote peer IP reachability problem.

 

While restarting the box , all sessions will close and the band width pool becomes free.  So the tunnel wouldn't have any problem to re-establish the connectivity.  That's the basic logic behind on this specific issue.. !

 

Let's wait to hear the expert opinion from TAC guys.

 

Cheers..

Nihas

 

Nihas [\b]
Nihas [\b]
Iz3k34l
New Contributor

I was also lead to believe it could be an encryption problem, like the encryption was too high which slowed things down under a large amount of throughput and caused these problems... maybe someone can confirm

thanson

We have 2x100D in HA(fw v5.0.9) with "low" throuput (10-5 Mbit/s) and this bug occured after 489 days of uptime.

Our support admin denied the root of the problem with 100d at first. After reboot ihe ip-sec far-ends immediately connected perfectly.

Labels
Top Kudoed Authors