Skip to main content
unknown1020
Explorer III
January 21, 2024
Question

Tunnel IPSEC in FortiGate

  • January 21, 2024
  • 5 replies
  • 2754 views

good morning friends.

I have configured an IPsec tunnel on my FW, however at first it was UP, after a few minutes the tunnel went down. The tunnel was raised manually then it fell in a few minutes and so on. What could be the problem? It has been validated that both computers have the same configuration.

5 replies

esalija
Staff
Staff
January 21, 2024

Hi @unknown1020 

 

Please run the IKE debug command while the issue is happening and check the output:

# diagnose debug reset

# diagnose vpn ike log-filter dst-addr4 <Remote_Peer_IP>

# diagnose debug application ike -1

# diagnose debug console timestamp enable

# diagnose debug enable

 

To disable :

# diagnose debug disable

# diagnose debug reset

 

For more details follow the KB step-by-step - > https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Troubleshooting-IPsec-Site-to-Site-Tunnel/ta-p/195672

 

Best regards,

Erlin

unknown1020
Explorer III
January 22, 2024

Friends, I managed to raise my tunnel, however when I ping the remote IP I have no response, what could be the problem?

IMG-20240122-WA0006.jpg

 

sahmed_FTNT
Staff & Editor
Staff & Editor
January 21, 2024

Hello, kindly make sure the below options are configured to make sure tunnel remains up:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-the-IPSec-auto-negotiate-and-keepalive/ta-p/189536

vbandha
Staff
Staff
January 21, 2024

Hello @unknown1020 

 

Also check Dead Peer Detection setting on both sides. 

Make sure it is set to 'On Demand' 

https://community.fortinet.com/t5/FortiClient/Technical-Tip-Configuring-DPD-dead-peer-detection-on-IPsec-VPN/ta-p/192616

 

Regards,

Varun

salemneaz
Staff
Staff
January 21, 2024

Do a continuous ping to the remote IP address to make sure that it is remaining up, and also change the mode to aggressive.

 

config vpn ipsec phase1-interface
edit <name>
set mode [aggressive|main]

 

Article Reference:

---------------------------------

https://docs.fortinet.com/document/fortigate/7.0.1/cli-reference/368620/config-vpn-ipsec-phase1-interface

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Differences-between-Aggressive-and-Main-mode-in/ta-p/196313

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPN-Phase-1-Process-Aggressive-Mode/ta-p/191185

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!