Forum Discussion

PrakashRIndia's avatar
PrakashRIndia
Icon for Staying Involved rankStaying Involved
2 months ago

IPSec Tunnel Active-Active Configuration Packet Loss Issue

Hi All,

We configured with IPSec Tunnel Active-Active Configuration but we are facing packet loss post Active-Active configuration on IPSec and forced to work on Active- Passive configuration which results in not using both links in the branch. We are using 2 Network links in the Branch and we have Fortinet SDWAN at Branch and IPSec tunnel is created to route all internet to Cato PoP .

We are trying to leverage "Multiple Active Tunnels for IPsec Sites "

4 Replies

  • Sharath's avatar
    Sharath
    Icon for Joining the Conversation rankJoining the Conversation

    Hi All,

    I would like to share the details on our recent troubleshooting with the CATO Support team, we observed the following behavior:

    - On the CATO POP side, the service is responding to all ingress requests. However, it appears that the POP is unable to consistently decide the correct return path for packets.

    - Due to this, we are experiencing 30–40% packet drops across both links, along with frequent tunnel flapping.

    - On our firewall end, continuous pings to external resources (e.g., Google DNS) and other IPsec tunnels show no packet loss. The issue only occurs when traffic is routed through the CATO IPsec tunnels in Active-Active mode.

    - We have applied the Network Rule configuration as recommended by the CATO team, but the issue still persists.

    - Interestingly, when configured in Active-Passive mode, the tunnels stabilize with no packet drops observed, and traffic flows without issue.

    At this point, it seems to be a limitation or unexpected behavior in how CATO handles path selection in Active-Active deployments.

     

  • michaelsaw's avatar
    michaelsaw
    Icon for Cato Professional Services rankCato Professional Services

    Hi PrakashRIndia,

    For the Active-Active WAN ISP Packet loss investigation, have you submitted a ticket with Cato Support team or with the ISP to investigate? 
    Do you encounter packetloss in Active-Active WAN and Active-Passive WAN scenarios?

    Cheers

    • PrakashRIndia's avatar
      PrakashRIndia
      Icon for Staying Involved rankStaying Involved

      Yes I have raised ticket vide 813967 but there is no resolution , they suggested many things to check but none worked. I have also shared PCAP files for review.

       We encounter packetloss in Active-Active WAN 

  • michaelsaw's avatar
    michaelsaw
    Icon for Cato Professional Services rankCato Professional Services

    Hi PrakashRIndia,

    Appreciate your feedback.

    Seems the issue occurs when the 2nd IPSec is connected.
    Would it be a good idea to review the IPsec configuration and pcap for both scenarios:
    (1) Standalone IPsec and
    (2) when the 2nd IPSec is connected?

    Seems that something is causing packetloss only when the 2nd IPSec is connected 🤔

    Cheers!