Skip to main content
TechTransit
New Member
February 16, 2022
Question

Ipsec Vpn not going up after wan failover

  • February 16, 2022
  • 1 reply
  • 1735 views

Hi,

I got a Dialup Ipsec Tunnel who is working fine between 2 FG until my wan change.

The remote FG, is the dialup one.It's seat behind a Aruba 9004 in gateway mode provide by the IPS wich i have little acces. The Aruba provide wan failover between wired and LTE.The issue is that the tunnel didn't go up when the wan change in the Aruba and i have to reboot the remote FG to get the tunnel back.

The wan interface on the remote FG got a private ip from the aruba.(192.168.x.x)

On my last troubleshooting i saw in the ipsec monitor from the remote fg that the phase1 was up but i never get the phase2 up.

I'm in agressive mode, i use local id.I try clearing session and ike gateway.

Remote FG: Fortigate 80E 6.4.4

HQ FG: Fortigate 100F 6.4.7

So! i don't know what i'm missing to get the tunnel back automatically when the wan change on the Aruba.

I'm wondering where the problem reside if everything work when rebooting the FG.

Thank in advance for some hints !

 

 

 

1 reply

Anthony_E
Staff
Staff
February 21, 2022

Hello,

 

Did you try to have a look in our Knowledge Base? You may find an article which could provide a solution.

Just select Knowledge Base, the concerned product and you can easily make a search in our search bar.

 

Do not hestiate to come back to us if you do not find the solution.

 

Regards,

Best Regards
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!