← Back to knowledge base
medium

Troubleshooting ADVPN with SD-WAN on FortiGate

Confirmed 9/15/2026

Problem

ADVPN peers, SD-WAN links, or traffic forwarding may not operate as expected. This procedure checks tunnel configuration and status, SD-WAN health and rule selection, sessions, routing, firewall policies, policy routes, packet flow, and debug output to isolate the issue.

Symptoms

Possible symptoms include disconnected ADVPN peers, failed SD-WAN health checks, traffic using an unexpected tunnel or route, intermittent route changes, or traffic being blocked or misrouted.

Environment

FortiGate configured with Auto Discovery VPN (ADVPN) and SD-WAN.

Root Cause

Potential causes include inconsistent ADVPN or SD-WAN configuration across FortiGates, unavailable peers or links, firewall rules preventing traffic, failed health checks, incorrect SD-WAN rule selection, policy-route behavior, or an unexpected active route. The specific cause must be identified from the collected output.

Solution

  1. Validate the ADVPN Phase 1 and Phase 2 configuration.
show vpn ipsec phase1-interface
show vpn ipsec phase2-interface
  1. Review the SD-WAN interface and load-balancing configuration.
show system sdwan-link-interface
show system sdwan-link-load-balance
  1. Check ADVPN gateway status. Replace <gateway-name> with the relevant gateway.
diagnose vpn ike gateway list
diagnose vpn ike gateway summary
diagnose vpn ike gateway info <gateway-name>
  1. Inspect SD-WAN links and link-monitor status. Replace <link-name> with the affected link.
diagnose sys sdwan link list
diagnose sys sdwan link info <link-name>
diagnose sys sdwan link-monitor status
diagnose sys sdwan link-monitor <link-name>
  1. Analyze SD-WAN members, rules, health checks, and sessions. Use service4 for IPv4 rules and service6 for IPv6 rules.
diagnose sys sdwan member
diagnose sys sdwan service4
diagnose sys sdwan service6
diagnose sys sdwan health-check
diagnose sys session filter ?
diagnose sys session list

Define an appropriate session filter before running diagnose sys session list to avoid displaying a potentially very large session table. Additional filter information is available in Technical Tip: Using filters to clear sessions on a FortiGate in the CLI.

  1. Collect SD-WAN and link-monitor debug output. The link-monitor command provides real-time link-monitor debugging. Reproduce the issue while debugging, then disable debugging.
diagnose debug reset
diagnose debug enable
diagnose debug application sdwan -1
diagnose debug application link-monitor -1
diagnose debug disable
  1. Confirm end-to-end configuration and reachability. Verify that ADVPN peers are connected to the network and that SD-WAN and ADVPN settings are consistent across all FortiGates. Review firewall rules for anything that may block ADVPN or SD-WAN traffic.

  2. Capture packets on the affected interface. Replace <interface> and <filter> with values appropriate to the traffic under investigation.

diagnose sniffer packet <interface> <filter> 6 0 l
  1. Trace traffic that is being misrouted. Determine the affected source and destination, then use flow debugging to observe policy evaluation and route selection. Replace <Source IP | Destination IP> with the relevant source or destination IP and replace N with the number of packets to capture.
diagnose debug reset
diagnose debug disable
diagnose debug flow filter clear
diagnose debug flow trace stop
diagnose debug flow filter addr <Source IP | Destination IP>
diagnose debug flow show function-name enable
diagnose debug flow show iprope enable
diagnose debug enable
diagnose debug flow trace start N
  1. Stop flow debugging after collecting the required output.
diagnose debug reset
diagnose debug disable
  1. Verify the active routing table. Confirm that the selected route matches the expected ADVPN and SD-WAN path.
get router info routing-table all
  1. Review firewall policies, configured policy routes, and policy routes generated by SD-WAN rules.
show firewall policy
show router policy
diagnose firewall proute list
  1. Correlate the results. Compare the active route, SD-WAN member and health-check state, generated policy routes, firewall policy match, flow-debug decision, and packet capture. Use these results to identify where incorrect route selection or traffic loss begins.

Related information: Technical Tip: SD-WAN support for ADVPN.

Verification

Confirm that the expected ADVPN peers appear as connected, SD-WAN members and health checks are operational, and the active routing table points to the intended path. Verify that diagnose firewall proute list reflects the expected SD-WAN rule, flow debugging shows the correct firewall policy and route selection, and packet capture confirms that traffic enters and exits through the intended interfaces.

Tags

No tags yet.

Community rating

— / 5 (0)

Discussion (0)

    No comments yet.