Question
Site to site IPSec VPN Tunnel failure on restart
I have a pair of Fortigate 60 3.0 MR7 Patch 2. I have set up a site to site IPSec VPN between them. The tunnel works. If I restart one of the routers then one or both of the routers are unable to bring up the tunnel until the phase 1 keylife expires on the router that didn' t restart. I can edit the phase 1 on the router that didn' t restart then bring up the tunnel from either router. Debug logs show that one router believes the tunnel is up and the other router believes the tunnel is down. When the tunnels won' t come up the router with the up tunnel refuses to discard the stuck SA. The router with the up tunnel may or may not discard the connection from the router with the down tunnel as unsolicited. The router with the down tunnel never gets a connection attempt because the router with the up tunnel communicates only over the stuck SA. Editing the phase 1 discards the phase 1 SA after which I can bring up the tunnel from either router. I have other Fortigate routers with a variety of firmware from 2.80 to 3.00 and all have the same IPSec VPN problem. A short keylife, DPD, auto-negotiate, and autokey keep alive are not acceptable solutions to this problem. I need Fortigate tunnels to be as reliable as Netscreen and Linksys tunnels which don' t have this problem.
