Skip to main content
Greggor25
New Member
July 2, 2019
Question

VPN Tunnel stays up but not traffic passing from our end

  • July 2, 2019
  • 1 reply
  • 11781 views

We have site to site VPN from Fortigate to Cisco.  The issue started out with DPD errors with tunnel dropping. We have corrected that issue.  The issue we're experiencing now is the tunnel stays up but we aren't able to send traffic to other end and traffic stops flowing.  I've noticed this happens between a rekey. This happens every eighteen hours. 

 

We've tried playing with settings by turning off DPD and back on.  I increased the lifetime seconds on P2 to 86400 to see if that will alleviate the issue.  We're natting a public IP for interesting traffic to their public subnets in P2 selectors.  I create a IP pool for that IP that allows everything from my internal network.  

 

Is anyone experiencing the same issue? 

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    July 2, 2019

    If you run IKE debug on the Cisco and FGT at the time the key expired, you should be able to see what failed. 

    But when we were using Cisco/FGT IKEv1 IPsec years ago we had some problem with DPD between them. So we disabled DPD and used IP SLA from the cisco side to keep the tunnel up. After migrated to IKEv2 DPD(INFORMATIONAL exchange) doesn't seem to cause problems so we're enabling it. 

    Also, I would suggest disabling anti-replay feature on both sides to see if it makes any difference in the debugging. 

    Greggor25
    Greggor25Author
    New Member
    July 9, 2019

    I've mentioned disabling anti-replay but haven't heard anything back. We don't maintain the Cisco on the other end. 

     

    Under P2 selectors I'm using named addresses that I've specified in FGT and remote end is using IP's. Would that make a difference?   

    rwpatterson
    New Member
    July 9, 2019

    Way back in the past it did. Not sure if it would now. I was on 4.x firmware.