Description | This article describes when the IPsec tunnel will be brought down if DPD is disabled in phase1. |
Scope | FortiGate. |
Solution |
The tunnel will be brought down when the keylife expires. Check the keylife with the following command:
diagnose vpn tunnel list
For example:
name=DisabledDPD ver=1 serial=8 10.47.1.188:0->10.47.4.65:0 tun_id=10.47.4.65 tun_id6=::10.47.4.65 dst_mtu=1500 dp proxyid_num=1 child_num=0 refcnt=4 ilast=43980886 olast=43980886 ad=/0 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.