Have two Fortigate 60F firewalls in Active/Passive HA. Previously had just 1 that was working as expected. Now, it seems as if one of the firewall polices just randomly stops working. We have a policy to allow inboind udp/tcp traffic on two ports. They work fine for a bit then it seems like 30-40 minutes after a firewall reboot they just stop forwarding traffic or receiving traffic at all. Rebooting the primary firewall causes the traffic to start flowing again. Sometimes it spontaneously starts passing traffic again after a couple of hours.

Shutting off the primary firewall and running it on the original firewall that was in before also causes the same issue.

The set up is 2 internet providers coming into a dumb switch, then the dumb switch plugs all the necessary ports into the two firewalls.

I’m trying to relay this as a third party so I may be missing some details, but any pointers would be greatly appreciated!

3 Spice ups

What fortiOS are you on? There are plenty of reported bugs in the past and probably still with certain revs where things like DoS policies or Traffic Shaping policies have caused issues, etc… Figuring out the release you are on, then looking at the release notes and bug reports will help see if you are suffering from a known issue. This could also be a memory leak or something resource related as well, so during those times of issue, are you seeing high CPU or memory usage for example?
Also, I would be remiss if I did not mentioned that a TAC case with Fortinet will probably get you quicker results since you are experiencing disruptions.

We aren’t seeing any high CPU/Memory usage during the times before/during/after the issue occurs.

We are getting ready to open a case right now :slight_smile:

We are on 7.4.7

Saw this in a Reddit thread about 7.4.7 and someone responded about bug ID 1057131 where a FortiGuard update can cause the system to not operate as expected if the FortiGate is already in conserve mode, but others have reported similar to what you are mentioning in that thread, so you might want to read through it.

https://www.reddit.com/r/fortinet/comments/1ii72xu/fortios_747/

Hope that helps.

1 Spice up

Still waiting to hear back from support, but we did downgrade the cluster to 7.2.10 meanwhile and it is still occurring.

I found this in a 7.4.5 recently… upgraded to 7.4.7 no change

IP somehow got changed to IPv6 for traffic
Changing back to IP-All / IP 0 fixed the issue…
Policy Objects > Services > IP >
Protocol Type IP
Protocol Options was 6 - set to 0 and resolved all sorts of issues…

Was passing some sessions from vlan to vlan without issues, and others it would burp here and there and fail most times.

This setting I don’t believe I ever changed, but never know.