Hi,
we set up an ADVPN Hub and Spoke VPN where:
Firmware is 7.4.9 version
The VPN works fine, anyway we have problems when some bad events occurs. For example if power goes off or the Hub lost some connectivity and HA switch the primary node, all IPSEC tunnels hangs (they are up but not working)
The only way to resume them is to restart every tunnel spoke side (waiting at least 10 seconds between down and up)
Does exist a way to avoid this situation? Why the HA switch causes the hanging?
Thanks
Hello pacionet,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
@pacionet Hi, You can take a look of KB below
This kind of issue requires a deep dive especially when the issue is happening, best approaching will be open case with TAC and engage them with live troubleshooting
Created on 01-08-2026 11:53 AM Edited on 01-08-2026 11:56 AM
Seconded, open a TAC case. Even if it turns out to be a known issue, tunnel issues are unlikely to be identified from a forum post unless they are extremely common. There are just too many different possible HA and VPN configurations, and too many possible network conditions.
Referencing pacionet's other forum reply, I can say known issue 1006759 is likely not a match since that issue is only reported for chassis FortiGates (6K/7K series)
| User | Count |
|---|---|
| 2910 | |
| 1451 | |
| 850 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.