FTDv outside interface problem
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-25-2023 04:44 AM - edited 03-25-2023 04:55 AM
I have a problem with my FTDv 7.3.1 on ESXi. When I start uploading a large file over L2L VPN using SCP or SFTP between the server and the remote host, after a while the outside FTDv subinterface becomes unavailable and IPSec is aborted. After a few minutes, the subinterface becomes available. I tried it many times and always I got this problem.
I tried restarting FTDv and the problem was fixed after that, but I don't know if it will come back again.
What can I do to find the cause and fix it?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-25-2023 06:45 AM
are you use any IP SLA ??
the icmp can drop before interface congestion and this make the interface UP/DOWN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-25-2023 12:40 PM - edited 03-25-2023 12:42 PM
No, I didn't set up an IP SLA. I have another FTDv in the same version. And it doesn't have that problem.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-26-2023 04:27 AM
check if there is any fragment that lead to high CPU utilize and this make some control packet drop and make the link flapping
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-26-2023 09:06 AM
Thanks for advice. Right now FTD is working well, I can't reproduce this issue, but I'll keep an eye on it.
