Skip to main content
Contributor III
November 27, 2010
Question

Unable to bring down IPSec VPN Tunnnel

  • November 27, 2010
  • 15 replies
  • 13871 views
Hi, i' ve configured FG200B as IPSec VPN Dialup Server, clients establish tunnels using FortiClient. but i m unable to bring down the tunnel from IPSec--->Monitor. even though clicking Bring down but still the tunnel is up :( using os 4.2 patch2 any idea??? thanks

    15 replies

    ede_pfau
    SuperUser
    SuperUser
    November 29, 2010
    I bet the tunnel IS torn down but will just re-establish immediately. You should see tunnel-down events in the event log. To prevent automatic tunnel negotiations look at the DPD option in phase 2. Additionally there is a CLI only setting (set auto-negotiate ena) that will re-establish a tunnel immediately. This is documented in the CLI Guide. And finally, the remote side configuration could be responsible for bringing up the tunnel - again, look at the logs.
    Contributor III
    November 30, 2010
    thanks, by default auto-negotiate is disable. i tried the DPD option both sides but still unable to terminate the tunnel forcefully. regards, Zeeshan
    ede_pfau
    SuperUser
    SuperUser
    November 30, 2010
    I see. Can you somehow prevent the remote user from dialing in? For example, stop him from authenticating. Use PSK plus local user auth. Again, do you see tunnel down events in the log?
    Contributor III
    December 2, 2010
    still no luck, i raised a ticket at TAC, they elevated it to L2 support. however i ran and submitted the diag output to them. isn' t there any command to bring down the tunnel? u r rite the tunnels break when i click bring down but soon re-establish.
    ede_pfau
    SuperUser
    SuperUser
    December 2, 2010
    diag vpn tunnel flush
    Contributor III
    December 2, 2010
    yeah, used that command. but again tunnel goes up soon
    abelio
    SuperUser
    SuperUser
    December 2, 2010
    ORIGINAL: Zeeshan Ahmed yeah, used that command. but again tunnel goes up soon
    to avoid guessing, could you post your phase1 and phase2 settings please? (real IPs are not necessary of course)
    ede_pfau
    SuperUser
    SuperUser
    December 7, 2010
    You could set it up like this: - set up local users on the FG (name+password) - configure each Fclient with localID==username and PSK==password_for_this_user. You can then either delete the user, change his password or just disable his/her temporarily. It' s one of the common scenarios explained in the IPSec VPN Handbook.
    Contributor III
    December 7, 2010
    this will work, but forticlients will b on automatic configuration, and they are authenticated using RADIUS server.
    ede_pfau
    SuperUser
    SuperUser
    December 7, 2010
    what will stop you from taking a user out of RADIUS then?? RADIUS or local user list, both are equivalent in this respect.
    Contributor III
    December 7, 2010
    user is successfully disconnected from RADIUS, but FG doesn' t go for authentication again
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!