This article describes this feature.
Solution
By default, dynamic interface is created when an IPsec is established.
When tunnel goes down, deleting the corresponding interface is very slow in the kernel and IPsec process has to wait for significant time.
If a number of tunnel goes down, IPsec process (iked) becomes stuck in D state and then, other tunnels are down by dpd timeout.
'set net-device', new route-based IPsec logic was introduced in 5.6.3 not to create an interface when tunnel is brought up and it is well explained in the KB article but its major impact is overlooked.
Even though the change is simple, that option has caused major outages in a number of large IPsec VPN network.Related Articles
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.