Problems with 5.4 VPN Tunnels
Hello,
This IPSEC VPN is becoming a major issue for our clients and seems to be some sort of bug. Got a few dozen 60E's running FortiOS 5.4 in hub and spoke configuration.
Issue as follows:
-Usually a single user at a branch site all of a sudden can't access some critical server in the hub site.
-The user can't ping the server over the tunnel, server can't ping the user over the tunnel
-User can ping EVERY other server and resource over the tunnel just fine.
What we've discovered:
-If we disable the tunnel interface on both Hub and spoke, then clear ARP on both fortigates, then bring both interfaces online, problem solved.....for awhile. It will come back, with some random user withing a week or two. This is of course disruptive to do in the middle of a day.
-We've discovered changing the remote branch user's local IP will "solve" the communication issue. And verified this is not an ip conflict issue. This is a quick and dirty fix, but is not a real solution. Sometimes better than doing the above fix as it wont bring the tunnel down.
-If you run a trace route from the affected system to the server it cant reach the hops after the local fortigate seem to attempt external networks....trace routing a server it can reach over the tunnel looks normal and hops through both internal interfaces of each spoke and hub unit.
As mentioned this has been happening at multiple clients we've implemented the same hub and spoke solution for. Tunnels have been configured differently, or rebuilt in some cases but the issue still seems to occur.
Any suggestions or help is appreciated.