Skip to main content
BK_LGW
New Member
June 15, 2020
Solved

Log/Counter For VPN Tunnel Down?

  • June 15, 2020
  • 4 replies
  • 8427 views

Hello all. A lot of remote access IPsec clients see random phase2 down messages. I was wondering how do i go about getting to the root cause of each phase2 down instance? I'd like to know if it was just due to DPD deciding FGT can't see the client for a period of time so it yanks the tunnel down or whatever else might cause it. Usually when DPD's the culprit, I see log messages about it prior to the phase2 down message. Can anyone point me in the right direction? 

    Best answer by emnoc

    I don't think the logs will be useful on telling you why a phase2 went down. Not sure on what you striving to get at. So many factors can determine why a vpn is disconnected, imho

     

    Ken Felix

     

    4 replies

    sw2090
    SuperUser
    SuperUser
    June 16, 2020

    if you happen to have some FOrtinet logging device connected to your FGT you could look into vpn event log there.

    Works fine here on our FortiManager.

    [strike]If not you could only look at ipsec debug log on cli instead as I don't think that this is in standard event log.[/strike]

    Correction: you see it on the FGT in the Log&Report menue under vpn events.

    BK_LGW
    BK_LGWAuthor
    New Member
    June 16, 2020
    Thank you for your reply. We do currently use FortiManager and that's where I can see that P2 message. However there are instances where the P2 goes down with no warning and no additional messages to explain why it happened. That's what I wanna get to the bottom of.
    emnoc
    emnocAnswer
    New Member
    June 16, 2020

    I don't think the logs will be useful on telling you why a phase2 went down. Not sure on what you striving to get at. So many factors can determine why a vpn is disconnected, imho

     

    Ken Felix

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.