cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
372
Views
1
Helpful
2
Replies

High UDP Traffic on Cisco RA VPN FTD

justclash4
Level 1
Level 1

Hi,
We have a weird issue with our RA VPN. We have a router at the edge. ASA-5508X with FTD image is behind the router. FTDv is behind the ASA and the gateway of FTDv is ASA and VPN IP Pool is 192.168.240.0- 192.168.255.255.

Our netflow server notified us about a high traffic usage from some of our users. for example:
A user (192.168.247.190) received 10GB from 157.240.0.63 on UDP 443 and I checked and found out that the user was not connected to VPN on that time.
we have received too much notifications like this and all of them are UDP traffic but destination is not limit to this IP and some other private IPs also exist like our PBX server which is working over UDP.

I saw the high traffic on the FMC health monitor panel and this was not the netflow system false positive.
I took a pcap from this flow and it was strange:

Screenshot 2025-04-29 at 2.06.22 PM.png

aa:aa:cc:cc:11:11 is mac address of FTDv and aa:aa:bb:bb:77:77 is mac address of ASA. 
this image is only a small part of this pcap and as you can see this is happening in nano seconds.

I couldnt find the root cause and decided to change the design and moved FTDv behind the router and the gateway of FTDv changed to router. After the change this issue not happened again.

we had to change the design again because the FTDv can not implement geographic limit for its RA VPN because the traffic is not going through FTDv and is going to FTDv.

We decided to setup a Fortigate between FTDv and Router and the gateway of FTDv changed to fortigate and after this change the random high UDP traffic happend again. but its not that huge like that time which ASA was the gateway.

This is the main Interface of FTDv graph:

Screenshot 2025-04-29 at 3.03.22 PM.png

this is HA State Link:

Screenshot 2025-04-29 at 3.01.21 PM.png

 FTDv Version is 7.4.2.1 and FMC is 7.4.2.1

I really appreciate your help.

2 Replies 2

justclash4
Level 1
Level 1

Any idea?

Try disable dtls for vpn and check

MHM