Skip to main content
Mehar
New Member
March 8, 2020
Question

IPSec VPN reconnect between HO and branch offices (behind router)

  • March 8, 2020
  • 2 replies
  • 3230 views

Hello all,

 

We are using Fortigate 60e in the Head office and 30e at the branch office. The branch office has a router from the ISP and can not be removed. I have successfully formed a site-to-site tunnel from branch office to HO using the wizards. For the BO i used the 'this site is behind a router' option.

 

VPN connects but over time it disconnects and then doesn't connect back automatically. Is there a way for the BO fortinet to initiate the connection automatically by itself? Is there some sort of a script for this because I didn't see any related settings unless I overlooked them?

    2 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    March 8, 2020

    I would recommend you set proper IPs on the tunnel interfaces on both sides, like 10.0.0.1/32 and 10.0.0.2/32 (don't forget to configure "set remote-ip" as well). Then run "link-monitor", which you can find many places how to, on the BO side to ping the HO IP. That would bring up (keep) the tunnel up when path problems are resolved.

    ede_pfau
    SuperUser
    SuperUser
    March 9, 2020

    Or fix the underlying problem, that is, check the idle timer settings in phase1 and phase2 ("set keepalive"), for IKE/SAs and NAT-Traversal. They must match on both sides. The BO firewall is initiating the tunnel (dial-in), so I suspect it's a NAT-T failure.

    Of course, a simple permanent ping will cover that hole as well...but not fix it.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!