Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
techonenl
New Contributor

IPSEC tunnel breaks when HA fails over

Hello,

 

We experience an issue where we have 2 Fortigate clusters in the same datacenter.

We have an Fortigate 100F cluster in Active-Passive with an IPSEC tunnel towards an Fortigate 60F cluster in Active-Passive.

 

Both are running the 6.4.9 firmware.

When the 100F cluster is running on the primary, traffic is passing along the IPSEC tunnel fine.

As soon as I failover the 100F cluster to the passive firewall, traffic stops passing (in both directions) along the tunnel. When I failover the 60F firewalls, this issue does NOT occur, and traffic keeps on passing.

 

The HA setup is the same, except for the 100F cluster which runs VDOM's (the IPSEC tunnel is NOT in the root VDOM) and the 60F cluster does NOT.

 

Anyone has seen this before and has the solution?

This issue does NOT occur when we failover the 60F cluster.

2 REPLIES 2
AEK
Honored Contributor II

Did you try to enable "session pickup" in HA config?

Well I'm not certain this will fix it but it's worth a try.

AEK
AEK
techonenl
New Contributor

Hi,

 

Yes, this feature has been enabled.

I also have enabled the set ha-sync-esp-seqno enable feature on the 100F cluster.

 

The strange part is: it only breaks when failing over the 100F cluster.

When failing over the 60F cluster everything keeps working fine.

 

I have also tried flushing the VPN tunnel after the failover, that doesn't help either.

 

Regards,

Labels
Top Kudoed Authors