Fortigate dropping packets from one single IP (which has proxy server)

Author
bt2020
New Member
  • Total Posts : 2
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/09/04 19:05:26
  • Status: offline
2020/09/04 19:14:44 (permalink)
0

Fortigate dropping packets from one single IP (which has proxy server)

Hello Fortians!

I am sorry I do not use Fortigate but I need your help with respect to Fortigate firewall.

I have a client who uses Fortigate firewall Fortigate 200D.

I provide them squid proxy server which uses Fortigate as its gateway.

Here is a scenario:

The client has many office branches which use my proxy as centralised proxy.

The problem is that when we put all branch traffic on proxy which in turn goes to Fortigate firewall, the Fortigate firewall starts dropping packets. (ping shows 50% packet loss to 8.8.8.8).

Wireshark packet monitor on proxy shows that ping request is going out but only 50% ping response coming back in from Fortigate gateway.

But when we put just 2-3 branches on proxy. Fortigate firewall does not seem to be dropping packets. Ping response shows no packet drops.


When the packet drop issue occurs then their other IPs are able to ping fine i.e. other IPs can ping 8.8.8.8 just fine.

So based on this my client says that its my proxy server's issue, that other IPs can ping 8.8.8.8 but not proxy server.

The proxy server logs are not showing any burden on proxy. So I believe that somewhere Fortigate blocks too much traffic coming from proxy and starts dropping packets from proxy server by considering it as somekind of attack.

Can you please tell me what settings need to be done so that Fortigate doesn't drop packets from proxy server?

I will be very grateful to you all for replies and help.

Thank you


Edit 1: Found model number Fortigate 200D
 
Amish
post edited by bt2020 - 2020/09/05 00:19:05
#1

1 Reply Related Threads

    SecurityPlus
    Gold Member
    • Total Posts : 367
    • Scores: 4
    • Reward points: 0
    • Joined: 2014/08/11 18:41:34
    • Status: offline
    Re: Fortigate dropping packets from one single IP (which has proxy server) 2020/09/10 18:09:52 (permalink)
    0
    I would think that it would be best to enlist the help of Fortinet tech support or a Fortinet consultant to troubleshoot this issue.

    FWF30E, FG40F, FG50E, FWF50E, FG60D, FWF60D, FG60E, FG60F, FG80E, FG100D
    FortiOS 5.2, 5.4, 5.6, 6.0, 6.2, and 6.4
    FortiSwitch FS-224E-POE
    FAP-221E, FAP-221C
    #2
    Jump to:
    © 2020 APG vNext Commercial Version 5.5