Skip to main content
WilliamK
New Member
December 3, 2013
Question

*SOLVED* Double IPSEC Tunnel settings for one

  • December 3, 2013
  • 6 replies
  • 6331 views
Hi, We' re using a Fortigate 200B and created a IPSEC route based tunnel. I have configured everything the way it has to be. The tunnel is working but when I monitor it to bring it up/down I see 2 tunnels for some reason. The second one is creating interference with the first one and I have no idea where it came from. Does anyone know how it is possible? The only thing that is different between the tunnels is the Proxy ID source. The top one is a range and the bottom one is a single IP address within that range. In the picture you can see what I can in the IPsec Monitor and the bottom part is the IKE setting, which clearly shows only the settings for one tunnel.

    6 replies

    rwpatterson
    New Member
    December 3, 2013
    Have you rebooted since messing with the tunnel definitions? I have seen strange things happen while I was making changes to phase 2 tunnel definitions. Sometimes I would get strange results. A reboot always cleared things up. There may be some value in just resetting the tunnels (renegotiating) instead. Your mileage may vary.
    WilliamK
    WilliamKAuthor
    New Member
    December 4, 2013
    Hi, I rebooted the system and the second tunnel disappeared. Thank you for the reply!
    oheigl
    New Member
    December 4, 2013
    I guess this could be happening if you have defined a address group in the destination network in the phase2 settings. Is this the case? Can you post your phase2 configuration?
    200B
    New Member
    December 4, 2013
    If you can' t reboot (in production) is there a particular process that can be restarted instead?
    WilliamK
    WilliamKAuthor
    New Member
    December 4, 2013
    I was able to reboot without any issues with other systems. I' m not sure if you can just restart services like you do on a server. Rebooting the firewall doesn' t take long at all.
    FortiRack_Eric
    New Member
    December 4, 2013
    Don' t reboot the unit, instead: diag vpn ike restart Cheers, Eric
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!