Skip to main content
Nordlo-Pajje
New Member
June 10, 2026
Question

Strange behaviour with Site to Site VPN with dynamic IP on on side.

  • June 10, 2026
  • 1 reply
  • 42 views

Hi all,

 

I saw a strange issue today when i was setting up a new VPN to a site. The site has one fiber connection and one 4G connection. I set the tunnel up as usual and i see both in the list under VPN. If i check the status och the VPN i only see the “primary” (fiber) connection and no 4G. If i the edit the firewall policy the secondary (4G) connection shows green/up.

If i the run diagnose vpn tunnel list i get

name=******-SEC ver=2 serial=52 x.x.x.x:0->0.0.0.0:0 nexthop=x.x.x.x tun_id=10.0.0.10 tun_id6=::10.0.0.10 status=down dst_mtu=0 weight=1
name=******-SEC ver=2 serial=54 x.x.x.x:0->0.0.0.0:0 nexthop=x.x.x.x tun_id=10.0.0.11 tun_id6=::10.0.0.11 status=down dst_mtu=0 weight=1

The site is not commissioned yet, hence the primary connection down.

1 reply

New Member
June 11, 2026

I’ve seen similar behavior with FortiGate IPsec tunnels using dynamic DNS. The tunnel may keep referencing the previous address until it re-resolves or the session is renegotiated. Good reminder to check DDNS updates, DNS cache, and tunnel monitoring settings.

doodle jump