Support Center > Search Results > SecureKnowledge Details
Traffic over VPN tunnel does not pass for several seconds during policy installation on Security Gateway (which causes traffic loss)
Symptoms
  • Traffic over VPN tunnel does not pass for several seconds during or after policy installation on Security Gateway (which causes traffic loss).

  • Kernel debug ('fw ctl debug -m fw + drop') shows:
    ... dropped by vpn_encrypt_chain Reason: encrypt drop;

  • Security Gateway with SAM card might enter a kernel panic (crash) in the following scenario:

    1. traffic is currently passing over VPN tunnel (encrypted UDP load)
    2. Security Gateway is rebooted
    3. instead of rebooting, Security Gateway enters a kernel panic
Cause
  1. VPN Link Selection is being reset during policy installation. This causes timeouts until VPN peers can be resolved again.

    Note: In some cases, certain VPN peers can take longer to re-establish, which would result in similar losses up to several minutes after policy push. (ID 02338534)
  2. SAM card might crash in certain scenario while processing VPN traffic (related to the above cause). (ID 02277594)


Solution
Note: To view this solution you need to Sign In .