Fortigate Strongswan IkeV2 Phase 2 Rekey
Hallo,
I have a problem in phase 2 with rekeying.
I have 7 location and my home office, at the location i have 2 30B v4.0,build0665, 3 80c v5.0,build0310, 1 60d v5.0,build0310 and 1 100D v5.0,build4429, at home i have a Server with Strongswan 4.5.2.
between the 100d and Strongswan is a static tunnel, the other Forti's are configured as responder and strongswan as initiator.
The keylifetime is 1800s, after this time the 100D delete child_sa and phase 2 ist down, but phase2 don't come up.
at the other location's i have a simular problem after rekeying in phase 2, i see phase 2 is up on both sites, when i ping a host, i don't get a answer. The package pass the tunnel and go to the host, the host send an answer, this package go in the tunnel interface from the forti, at home i don't see this package on the lan-interface from my Server. Strongswan is configured with inactivity option (300s). After 300s phase2 go down. if i ping a host, i get an answer.
Does anyone have experience with Forti and Strongswan?
Thanks
Sorry but my english is not the best.
