Skip to main content
fortiuser60d
New Member
October 5, 2016
Question

Problem with multiple ipsec vpn tunnels.

  • October 5, 2016
  • 4 replies
  • 21919 views

I configure ipsec vpn on Fortigate 60D with firmware version 5.4.1. I create the first tunnel (VPN1) and I check the vpn connection. Everything is OK. I create second one (VPN2) and both VPNs (VPN1 and VPN2) work. And then I create the third tunnel (VPN3) on fortigate. I check the connections VPN1, VPN2, VPN3, it works only the last one (VPN3 (pass), VPN1 (failure), VPN2(failure)). When I delete the last created vpn (VPN3), both VPNs (VPN1 and VPN2) work. How can I create more than two ipsec vpn tunnels?

4 replies

TuncayBAS
Explorer
October 5, 2016

please write hear following command result. but then create three vpn.

 

 

 

dia debug app ike 255

dia debug en

 

 

ede_pfau
SuperUser
SuperUser
October 5, 2016

You can create dozens of VPN tunnels, that's no problem. In your case the config of the 3rd tunnel contains some element which blocks the other tunnels, like a duplicate remote IP address, or identical Quick Mode selectors in phase2.

 

You should post (in text form) the phase1 and phase2 configs, then we'll see.

emnoc
New Member
October 5, 2016

 

Output from the following cli cmd;

 

 

diag vpn tunnel list

diag vpn ike gateway

get router info routing all

 

 

Keep in mind you can create as many ipsec-tunnel as the platform max matrix values.  if you on a dialup vpn, you can unique define these by a local-id per peer value set  in the phase1 config.

 

Also to add to ede, there probably something else screwing up  the  other 2, I would not hesitate to add any routing-issues  if we are using a "route-based" vpn.

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!