Skip to main content
Gypsy_Dave
New Member
August 14, 2020
Question

Site-to-site VPN disconnecting problems. DDNS on one end.

  • August 14, 2020
  • 6 replies
  • 6559 views

Hi all,

I've seen many posts about this but cant find an answer. I have an HQ with a FG80E and a branch office with a FG30E. I've created a site to site VPN. The HQ used a fixed IP public address and the branch used DDNS. The VPN was working for about a day and now it's gone down. The only way I can get it back online is to reboot the FG30E. This happens every so often.  DDNS always resolves correctly.

 

I've ran the debug on the HQ site and the debug is attached in the text document. 

 

thanks,

 

 

 

    6 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    August 14, 2020

    Probably you need to open a TT at TAC to get this taken a look at. But my concern in the IKE debug log is:

    "remote port change 23336 -> 23422"

    every time after PSK was confirmed. I'm wondering if there is a NAT device in-between and swtiching/translating the  port after a while. If the 30E is NOT getting the dynamic public IP, use aggressive mode, which doesn't require DDNS.

    Gypsy_Dave
    New Member
    August 14, 2020

    Between the FG30E and internet there is a cable router. Could this be the problem? I setup the branch office side as NAT in between VPN connection. Is this correct if there is something between the FG and the internet connection?

    Thanks,

    Toshi_Esumi
    SuperUser
    SuperUser
    August 14, 2020

    My question was if the 30E gets the public IP from the Cable co. Or just get a private IP like 192.168.0.x from the cable router.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.