IPsec tunnel gone down and never up again
Hi, Everyone. I've two FortiGate firewalls (200E,40F0). I created an IPsec tunnel between the two of them . after some days tunnel goes down and never back again. I must Delete the tunnel on both devices and create again new tunnel. I check my Internet connection is ok. when I debug the out of IPsec its show Request on The queue and negotiation timeout
I follow the Fortigate cookbook for creating IPsec Tunnel. I created phase1, phase2, two policies, and a static route.
FortiGate 200E has v6.4.7 build1911 (GA)
Fortigate 40F has v6.4.5 build1828 (GA)
===================Debug output=====================
this the diagnose debug application ike -1
tcci # diagnose debug enable
tcci # ike 0:airport:lan-acc-aiport: IPsec SA connect 17 xxx.xxx.43.114->xxx.xxx.185.68:0 ike 0:airport:lan-acc-aiport: using existing connection ike 0:airport:lan-acc-aiport: config found ike 0:airport: request is on the queue ike 0:airport:13: negotiation timeout, deleting ike 0:airport: connection expiring due to phase1 down ike 0:airport: deleting ike 0:airport: deleted ike 0:airport: schedule auto-negotiate ike shrank heap by 159744 bytes ike 0:airport:lan-acc-aiport: IPsec SA connect 17 xxx.xxx.43.114->xxx.xxx.185.68:0 ike 0:airport:lan-acc-aiport: config found ike 0:airport: created connection: 0x141412f0 17 xxx.xxx.43.114->xxx.xxx.185.68:500. ike 0:airport: IPsec SA connect 17 xxx.xxx.43.114->xxx.xxx.185.68:500 negotiating ike 0:airport: no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation ike 0:airport:14: out DB2D383C185D9F600000000000000000212022080000000000000140220000300000002C010100040300000C0100000C800E0080030000080200 0005030000080300000C0000000804000005280000C8000500005BBC21C131AAE8448354229E35242CD0D2F03F560F61C48D958C5B02342980FD32582CBA246F1BFD3687B6 A37E701F13FC21789721CAE4FDB4E63AFD0C8C20B555DD649D5ABB48ECF522F6C40B35DB0FF8B6C0147BBC8E6934FC1FC07192EB0255E3F6BE6BD4E4110F0488FE261CC047 E2B90BB2D67477A14366B3B28928E35F5433BCABCF5D74CC79C15EA965E85CAB27E31B9506447B308AA091A64A4D03B15C4A4E3A09C913FE84D2E01B863707FFEBD419C8E3 20EDCB270E55AD6FADF5D4290000240767E9EF4BA2466AF23574BD1FF736E9D4AB92209281CB1E27A24E6A33F58322000000080000402E ike 0:airport:14: sent IKE msg (SA_INIT): xxx.xxx.43.114:500->xxx.xxx.185.68:500, len=320, id=db2d383c185d9f60/0000000000000000 ike 0:airport:14: out DB2D383C185D9F600000000000000000212022080000000000000140220000300000002C010100040300000C0100000C800E0080030000080200 0005030000080300000C0000000804000005280000C8000500005BBC21C131AAE8448354229E35242CD0D2F03F560F61C48D958C5B02342980FD32582CBA246F1BFD3687B6 A37E701F13FC21789721CAE4FDB4E63AFD0C8C20B555DD649D5ABB48ECF522F6C40B35DB0FF8B6C0147BBC8E6934FC1FC07192EB0255E3F6BE6BD4E4110F0488FE261CC047 E2B90BB2D67477A14366B3B28928E35F5433BCABCF5D74CC79C15EA965E85CAB27E31B9506447B308AA091A64A4D03B15C4A4E3A09C913FE84D2E01B863707FFEBD419C8E3 20EDCB270E55AD6FADF5D4290000240767E9EF4BA2466AF23574BD1FF736E9D4AB92209281CB1E27A24E6A33F58322000000080000402E ike 0:airport:14: sent IKE msg (RETRANSMIT_SA_INIT): xxx.xxx.43.114:500->xxx.xxx.185.68:500, len=320, id=db2d383c185d9f60/0000000000000000 ike 0:airport:lan-acc-aiport: IPsec SA connect 17 xxx.xxx.43.114->xxx.xxx.185.68:0 ike 0:airport:lan-acc-aiport: using existing connection ike 0:airport:lan-acc-aiport: config found ike 0:airport: request is on the queue ike 0:airport:14: out DB2D383C185D9F600000000000000000212022080000000000000140220000300000002C010100040300000C0100000C800E0080030000080200 0005030000080300000C0000000804000005280000C8000500005BBC21C131AAE8448354229E35242CD0D2F03F560F61C48D958C5B02342980FD32582CBA246F1BFD3687B6 A37E701F13FC21789721CAE4FDB4E63AFD0C8C20B555DD649D5ABB48ECF522F6C40B35DB0FF8B6C0147BBC8E6934FC1FC07192EB0255E3F6BE6BD4E4110F0488FE261CC047 E2B90BB2D67477A14366B3B28928E35F5433BCABCF5D74CC79C15EA965E85CAB27E31B9506447B308AA091A64A4D03B15C4A4E3A09C913FE84D2E01B863707FFEBD419C8E3 20EDCB270E55AD6FADF5D4290000240767E9EF4BA2466AF23574BD1FF736E9D4AB92209281CB1E27A24E6A33F58322000000080000402E ike 0:airport:14: sent IKE msg (RETRANSMIT_SA_INIT): xxx.xxx.43.114:500->xxx.xxx.185.68:500, len=320, id=db2d383c185d9f60/0000000000000000 ike 0:airport:lan-acc-aiport: IPsec SA connect 17 xxx.xxx.43.114->xxx.xxx.185.68:0 ike 0:airport:lan-acc-aiport: using existing connection ike 0:airport:lan-acc-aiport: config found ike 0:airport: request is on the queue ike 0:airport:lan-acc-aiport: IPsec SA connect 17 xxx.xxx.43.114->xxx.xxx.185.68:0 ike 0:airport:lan-acc-aiport: using existing connection ike 0:airport:lan-acc-aiport: config found ike 0:airport: request is on the queue ike 0:airport:lan-acc-aiport: IPsec SA connect 17 xxx.xxx.43.114->xxx.xxx.185.68:0 ike 0:airport:lan-acc-aiport: using existing connection ike 0:airport:lan-acc-aiport: config found ike 0:airport: request is on the queue ike 0:airport:14: out DB2D383C185D9F600000000000000000212022080000000000000140220000300000002C010100040300000C0100000C800E0080030000080200 0005030000080300000C0000000804000005280000C8000500005BBC21C131AAE8448354229E35242CD0D2F03F560F61C48D958C5B02342980FD32582CBA246F1BFD3687B6 A37E701F13FC21789721CAE4FDB4E63AFD0C8C20B555DD649D5ABB48ECF522F6C40B35DB0FF8B6C0147BBC8E6934FC1FC07192EB0255E3F6BE6BD4E4110F0488FE261CC047 E2B90BB2D67477A14366B3B28928E35F5433BCABCF5D74CC79C15EA965E85CAB27E31B9506447B308AA091A64A4D03B15C4A4E3A09C913FE84D2E01B863707FFEBD419C8E3 20EDCB270E55AD6FADF5D4290000240767E9EF4BA2466AF23574BD1FF736E9D4AB92209281CB1E27A24E6A33F58322000000080000402E ike 0:airport:14: sent IKE msg (RETRANSMIT_SA_INIT): xxx.xxx.43.114:500->xxx.xxx.185.68:500, len=320, id=db2d383c185d9f60/0000000000000000 ike 0:airport:lan-acc-aiport: IPsec SA connect 17 xxx.xxx.43.114->xxx.xxx.185.68:0 ike 0:airport:lan-acc-aiport: using existing connection ike 0:airport:lan-acc-aiport: config found ike 0:airport: request is on the queue ike 0:airport:14: negotiation timeout, deleting ike 0:airport: connection expiring due to phase1 down ike 0:airport: deleting ike 0:airport: deleted ike 0:airport: schedule auto-negotiate ike 0:airport:lan-acc-aiport: IPsec SA connect 17 xxx.xxx.43.114->xxx.xxx.185.68:0 ike 0:airport:lan-acc-aiport: config found ike 0:airport: created connection: 0x141412f0 17 xxx.xxx.43.114->xxx.xxx.185.68:500. ike 0:airport: IPsec SA connect 17 xxx.xxx.43.114->xxx.xxx.185.68:500 negotiating ike 0:airport: no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation ike 0:airport:15: out C055F5FE2DBDE3970000000000000000212022080000000000000140220000300000002C010100040300000C0100000C800E0080030000080200 0005030000080300000C0000000804000005280000C80005000032476C8A821988F89B3A9DC1B03DB7A85AA02C1AA1811177B275B788219C3CB475330DB57CDEA601969222 E5FDDDA83989644EC5007BD5E5214A69DFBF423239343CA6019D17528EF5EC6A114E87A40B30236D0BDDB6F1379D72A5C9A75D58C990E8F71926FD49EAC71AD2DEE11D0956 F22F7CD8B7855D5B67C043FDF71347EC951652F10379C4163B14474D79EAE2E2421E1E1E76EF977BE5B392648831A84E446761BFD1451754D17494FFFA78980043C4F18B5B 0DC001F4C9E592B8FA5A1B29000024E3C3F8E36F1F53895DB965DF4A9BB51B30A8081ABFE5631FB2F6AB198F6C9E85000000080000402E ike 0:airport:15: sent IKE msg (SA_INIT): xxx.xxx.43.114:500->xxx.xxx.185.68:500, len=320, id=c055f5fe2dbde397/0000000000000000 tcci # ike 0:airport:15: out C055F5FE2DBDE3970000000000000000212022080000000000000140220000300000002C010100040300000C0100000C800E00800300 000802000005030000080300000C0000000804000005280000C80005000032476C8A821988F89B3A9DC1B03DB7A85AA02C1AA1811177B275B788219C3CB475330DB57CDEA6 01969222E5FDDDA83989644EC5007BD5E5214A69DFBF423239343CA6019D17528EF5EC6A114E87A40B30236D0BDDB6F1379D72A5C9A75D58C990E8F71926FD49EAC71AD2DE E11D0956F22F7CD8B7855D5B67C043FDF71347EC951652F10379C4163B14474D79EAE2E2421E1E1E76EF977BE5B392648831A84E446761BFD1451754D17494FFFA78980043 C4F18B5B0DC001F4C9E592B8FA5A1B29000024E3C3F8E36F1F53895DB965DF4A9BB51B30A8081ABFE5631FB2F6AB198F6C9E85000000080000402E ike 0:airport:15: sent IKE msg (RETRANSMIT_SA_INIT): xxx.xxx.43.114:500->xxx.xxx.185.68:500, len=320, id=c055f5fe2dbde397/0000000000000000 tcci # diagnose deike 0:airport:lan-acc-aiport: IPsec SA connect 17 xxx.xxx.43.114->xxx.xxx.185.68:0 ike 0:airport:lan-acc-aiport: using existing connection ike 0:airport:lan-acc-aiport: config found ike 0:airport: request is on the queue
========IPsec Configuration Phase1 ================
tcci # show vpn ipsec phase1-interface airport config vpn ipsec phase1-interface edit "airport" set interface "wan1" set ike-version 2 set local-gw xxx.xxx.43.114 set peertype any set net-device disable set proposal aes128-sha256 set dhgrp 5 set nattraversal disable set remote-gw xxx.xxx.185.68 set psksecret ENC next end
config vpn ipsec phase1-interface edit "tcci" set interface "wan" set ike-version 2 set local-gw xxx.xxx.185.68 set peertype any set net-device disable set proposal aes128-sha256 set dhgrp 5 set nattraversal disable set remote-gw xxx.xxx.43.114 set psksecret ENC next end
======================Sniffer packets====================
tcci # diagnose sniffer packet any "host xxx.xxx.185.68" interfaces=[any] filters=[host xxx.xxx.185.68] 2.403202 xxx.xxx.43.114.500 -> xxx.xxx.185.68.500: udp 320 2.429283 xxx.xxx.185.68.500 -> xxx.xxx.43.114.500: udp 304 8.406283 xxx.xxx.43.114.500 -> xxx.xxx.185.68.500: udp 320 8.431885 xxx.xxx.185.68.500 -> xxx.xxx.43.114.500: udp 304 20.406906 xxx.xxx.43.114.500 -> xxx.xxx.185.68.500: udp 320 20.440803 xxx.xxx.185.68.500 -> xxx.xxx.43.114.500: udp 304 30.404825 xxx.xxx.43.114.500 -> xxx.xxx.185.68.500: udp 320 30.460290 xxx.xxx.185.68.500 -> xxx.xxx.43.114.500: udp 304 33.407891 xxx.xxx.43.114.500 -> xxx.xxx.185.68.500: udp 320 33.429407 xxx.xxx.185.68.500 -> xxx.xxx.43.114.500: udp 304 39.403850 xxx.xxx.43.114.500 -> xxx.xxx.185.68.500: udp 320 39.425268 xxx.xxx.185.68.500 -> xxx.xxx.43.114.500: udp 304 12 packets received by filter 0 packets dropped by kernel
