Hi,
We recently replaced a Huawei firewall with a FortiGate at our HQ site and started seeing an intermittent IPSec issue.
Our setup is hub-and-spoke:
During POC testing, everything worked as expected.
IPSec tunnels came up successfully, traffic passed normally, and connectivity was stable.
After deploying into the customer environment, we noticed the following behavior after approximately 6 hours:
DPD is enabled (on-idle, retry count 3, interval 20 seconds).
No configuration changes or reboots occur when the issue happens.
This behavior did not occur during POC and only appears in the customer environment.
Replacing Huawei with FortiGate is the main change.
At this point, we cannot conclusively determine whether upstream network devices are involved.
We are mainly looking for guidance on how to make the IPSec tunnel more resilient in this scenario.
Has anyone seen similar behavior with FortiGate IPSec?
What configuration changes or design adjustments would you recommend to prevent the tunnel from entering this state?
HI,
This forum is specifically for FortiGate VM deployments in Microsoft Azure. For your issue I suggest you open a support ticket where our staff can review the logs with you regarding the IPSEC tunnels issues. Most likely the settings might be a bit different between a FortiGate VM and Huawai firewall.
You can find contact details below:
https://www.fortinet.com/support/contact
Regards,
Joeri
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.