Skip to main content
Contributor III
January 16, 2011
Question

The VPN tunnel goes down

  • January 16, 2011
  • 12 replies
  • 8486 views
I have a FortiGate 50B firmware 3.00-b0730 (MR7 Patch 1) with 10 VPN IPSec fully functional (to Cisco devices, jupiter etc.) of my clients, I migrated the VPN to a FortiGate 200B firmware v4.0, build0303, 101214 (MR2 Patch 3) with the same configuration, but i found numerous problems with some device vpn for example with a Cisco ASA 5520 with software release 8.2 (2). At first, the tunnel is established perfectly, but after a some hours, the tunnel goes down and I have to reset the tunnel. Why? What has changed from version 3.00-b0730 (MR7 Patch 1) the fully functional version v4.0, build0303, 101,214 of the FortiGate? thanks

    12 replies

    rwpatterson
    New Member
    January 16, 2011
    A couple of questions regarding the new unit: 1) Did you migrate the tunnels over from scratch? 2) Did you copy the config with the tunnels then upgradethe 200B? 3) Did you cut/paste the tunnels into the CLI?
    Contributor III
    January 16, 2011
    Hello, I did not do copy and paste, I got the new device I upgraded the firmware and then I typed the commands to create the vpn.(with the same parameters).
    Contributor III
    January 26, 2011
    Seems like we have the same issue with our FG1240B, 4.0 MR1 build 5135. If no traffic is flowing in the tunnel, it goes down and we have to manually bring up the tunnel again. to rwpatterson : 1. No. 2. Yes. 3. We did cut and paste the tunnels via CLI. Thanks in advance
    Contributor III
    January 31, 2011
    Hello. I opened a ticket to the FortiGate service center (Type P3), but they do not respond from a week. For me it' s a bug in the new version, ... You know how I can open a complaint in the Headquarter? there Is anyone of the development team of FortiGate in this forum? Help me!!!
    rwpatterson
    New Member
    February 1, 2011
    @ FraArm: In the phase 2 definition for the tunnel, try adding:
    set auto-negotiate enable
    @rhetsky Please start a new post.
    ede_pfau
    SuperUser
    SuperUser
    February 2, 2011
    just as a suggestion: if the FG200B is in production environment and management is pressing you, why not downgrade to 3.00MR7 patch 10 (latest) and have it working? You stated that with 3.00 MR7 you had no problems. You could even put the 50B back into operation and solve the issue in the lab. One more hint: we had massive problems after upgrading from 4.1.2 to 4.1.6 in that the VPNs came up but failed repeatingly. They couldn' t stay up for more than minutes. It turned out that the firmware version activated IPSec offloading to the NPs. As your 50B doesn' t have NPs but the 200B does, it might be that offloading causes your troubles. There are CLI commands to disable offloading which might be worth trying (conf system npu). Fortinet TAC should be able to help you in this direction.
    Contributor III
    February 2, 2011
    Hello ede_pfau, I can not downgrade because the FortiGate 50B only supports 20 tunnels. I do not complain to the problem with the vpn, because the problems in this work are ordinary but for the assistance. They could not tell me that there are problems and are solving them, rather than bounce the problems? I pay a regular service, and i do not accept that support will not answer me for 1 week otherwise why I must pay the service? Thanks for your reply, after I try to apply your suggestion, and I' ll let you know.
    ede_pfau
    SuperUser
    SuperUser
    February 5, 2011
    Can you live with that short interruption if you set the key lifetime to the max?
    Contributor III
    February 5, 2011
    the problem is only one, I have a call center 24 hour 7x7 and in this tunnel VPN there are calls and the web services...the interruption creates problems for the VoIP calls.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.