IPsec S2S Tunnel Up but No Traffic Until Manual Restart (FortiGate 80F MikroTik)
Hello,
I have a Site-to-Site IPsec VPN between a Fortinet FortiGate 80F and a MikroTik router.
Phase1 and Phase2 parameters match on both sides. The tunnel shows status = up, but no traffic passes until I manually restart the tunnel on the FortiGate.
After restart:
Traffic works normally
SA counters increase
Both directions pass traffic
After some time, traffic stops again while:
Phase1 remains up
DPD status is OK
No config changes are made
In diagnose vpn tunnel list, sometimes I see:
proxyid_num=0 / child_num=0
or
asymmetric counters (only enc or only dec increasing)
Is it possible for Phase1 to stay up while Phase2 becomes unusable?
Could this be related to NPU offloading or replay protection?
FortiOS version: 7.4.11
Any guidance would be appreciated.
#FortiGate