Skip to main content
Print

Packet Drop Issues

Please Verify the Following Configuration:

  • PATHMTU, MSSFIX
  • Packet Fragmentation
  • Link Flapping
  • DDoS
  • Firewall (DPI)
  • Filtering
  • IPS/IDS
  • QoS Configuration
  • Routing Issues

DDoS

  • Verify if DDoS protection is enabled on the WAN interface.
  • Check if incoming packets have source IPs flagged as spoofed addresses.
  • Determine if the IP is flagged for an attack or port scan:
    • IPs flagged as part of an attack are blocked for 5 minutes.
    • IPs flagged as part of a port scan are blocked for 1 day.
    • If the IP is mistakenly blocked, add it to the Allowlist or adjust the DDoS threshold limits.

Firewall

  • Check the Firewall → SDWAN_FORWARD chain for any rules that might be dropping packets.

Filtering

  • Verify if the IP subnet is listed under the IP Block List.
  • Check if the MAC address is added under MAC Filtering.

IPS/IDS

  • Review the IPS/IDS Alerts to see if the packet was flagged as a threat.

Routing Issues

Branch to Branch and Branch to Branch via DC Connectivity Issues

  • Ensure the NetBalancer gateway IP matches the branch's specific tunnel IP.
    • Incorrect gateway IPs will misdirect packets, preventing proper routing.
    • Verify settings in the NetBalancer page.
  • Ensure LAN subnets do not overlap across branches when using NetBalancer for LAN-to-LAN communication.
    • Verify subnet configurations on the Interfaces pages of each branch.
Table of Contents