{{ secondMenu.name }}
Issue Type
Typical Symptom
Root Cause
Troubleshooting Method
Resolution Suggestion
Policy Not Hit
No logs, traffic denied by default
Mismatch or wrong order
Enable hit count, adjust order
Optimize policy order
NAT Conversion Error
No public source IP on outbound traffic
NAT not enabled or wrong address pool
Packet capture to confirm egress IP
Check NAT setting
VPN Not Established
Tunnel DOWN
Key or encryption mismatch
show vpn ipsec sa for negotiation logs
Align encryption parameters
Authentication Failure
Portal error or timeout
AD misconfiguration or timeout
Test AD connection
Check bind account, port, SSL
Object Conflict
Same name for different IPs
Duplicate after conversion
Search duplicate names
Merge or rename manually
HA Failover Failure
No switchover or abnormal state
Sync link error
Check HA status and heartbeat
Verify HA link
Unstable Traffic
Frequent session rebuild
Session tracking inconsistency
Check session table
Adjust session aging time
Missing Logs
Traffic normal but no logs
Log recording disabled
Enable “Log Traffic”
Turn on and retest