Assuming an IPSec VPN connection to 'FortiGate B' or 'Vendor Firewall' has already been configured from 'FortiGate A'.If for any reason, the remote FortiGate/firewall unit is rebooted, an administrator may wish to have this IPSec tunnel come back up automatically, meaning before any traffic is initiated.
For this to happen, a CLI Phase 2 setting must be enabled in configuration of all those tunnels, which should automatically recover when necessary and be brought up immediately.
From CLI.
For route based IPSec:# config vpn ipsec phase2-interfaceFor policy based IPSec:
edit <name>
set auto-negotiate enable
end# config vpn ipsec phase2It is also possible to enable from GUI:
edit <name>
set auto-negotiate enable
end
GUI – VPN – IPsec Tunnels – VPN tunnel name – Phase2 selectors – Advanced – Auto-negotiate.
Related Articles
Technical Tip: How to configure VPN Site to Site between FortiGates (Using VPN Setup Wizard)
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.