Tunnel won´t go UP after Cluster Testing
Hi,
are you ready for my first post in this forum?
So i want to connect a small office to our Headquarter with a VPN IPSec Tunnel. In the small office we have two seperate ISP-connections were we have a FortiGate 30E Active-Passive Cluster.
FortiGate #1 WAN ->ISP-Router #1 LAN4
FortiGate #1 LAN4 ->ISP-Router #2 LAN3
FortiGate #2 WAN ->ISP-Router #1 LAN4
FortiGate #2 LAN4 ->ISP-Router #2 LAN3
So i have done two VPN Connections (VPN#1 and VPN#2. For each ISP Router one connection). The second connection (VPN#2) is defined as a Backup Line with "set monitor VPN#1".
So i have done some redundancy tests.
1. Shutdown the first ISP-Router. After five Pings lost, i had a new connection with the second tunnel.
2. First ISP-Router is down and i will shutdown the active FortiGate. Now the second tunnel can´t get up! I can do pings to the interface of the second router and i can do pings to any adress in internet as well. But no vpn connection will start.
Powering on the first ISP-Router, will start the first tunnel up.
Does anybody can help me with this?
Best Regards
Roshan
