IPSEC phase 1 SA lifetime not honouring configured setting of 28800
hi
I am trying to figure out why our fortigate configuration is not honouring the phase 1 lifetime setting of 28800s (8hrs)
Over the weekend I started monitoring the tunnel with pingplotter and noticed a clear pattern as to when the phase 1 rekey happens.
the rekey would start the process after 7hrs 38min, not the 8hrs as configured on the fortigate.
the other thing thats happening is that during this time, network connectivity between the fortigate and azure is down for about 45-60s.
using pingplotter i can see a clear pattern with this and that the rekey happens every 7hrs38min
(excluding full tunnel drops) causing network connectivity issues along the way.
here are the time stamps from pingplotter showing phase1 rekey.
the tunnel drop timestamp indicates that the full tunnel went down.
17/01 - 15:43
17/01 - 23:20 + 7hrs 37min
18/01 - 06:58 + 7hrs 18min (tunnel drop)
18/01 - 14:36 + 7hrs 38min
18/01 - 22:14 + 7hrs 38min
19/01 - 05:52 + 7hrs 38min
19/01 - 13:29 + 7hrs 37min
19/01 - 21:07 + 7hrs 38min
20/01 - 04:45 + 7hrs 38min
20/01 - 12:23 + 7hrs 38min
20/01 - 20:01 + 7hrs 38min (tunnel drop)
21/01 - 03:39 + 7hrs 38min
21/01 - 11:17 + 7hrs 38min
as you can see, a distinct pattern is visible.
i have cross checked all these times with app errors, tasks/schedules, fortigate logs etc and they all match up.
so my question is...
does anybody know how or why the phase 1 lifetime setting is not working as expected? is this a bug?
7hrs38min is a very random time but its consistent. Also weird that during this time we lose network connectivity.
has anybody seen/come across something like this before?
i have raised a ticket with support and waiting for a reply
fortigate details
Fortigate 1800F
v7.2.9 build 1688
cheers,
