Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
S_McD
New Contributor

Are there any known issues with version 5.2.4 and IKE Tunnel within an IKE Tunnel?

Hi,

 

We currently have two FortiGate 60D's connecting one of our remote sites to our main site via a VPN tunnel, which seems to be working fine without any issue. Now running across that tunnel we have two AeroHive access points which creates its own IKE tunnel to initiate a tunnel between the two access points along this VPN connection. The problem is that randomly, and without any reason as far as we can see the VPN tunnel between the APs drops around 6-10 times a day. Now we can re-establish the connection by rebooting the remote AP but continually monitoring this connection to reboot the AP so frequently isn't ideal. In the IKE logs for the APs you see:

 

[size="2"]2015-11-30 19:02:45:Phase 1 deleted(x.x.x.x[4500]->x.x.x.x[4500]) (Remote AP -> Main AP)[/size] [size="2"]2015-11-30 19:02:45:Phase 1 started(x.x.x.x[500]->x.x.x.x[500]) (Remote AP -> Main AP)[/size] [size="2"]2015-11-30 19:03:35:Peer not responding(x.x.x.x[500]->x.x.x.x[500]) (Remote AP -> Main AP)[/size]

 

Now using the APs built in utilities you are able to ping each AP in both directions and get a response between the Remote AP and the Main AP but for some reason the tunnel continually drops after some time.

The issue is a bit strange as we've only had this problem since we've installed these Fortigate firewalls at both sites but we also upgraded the firmware to 5.3.4 at the same time.

 

I've spoken to our AeroHive support company and they can't seem to figure out what the problem is, especially as this used to work, so I thought I'd ask here to see if anyone knows of any known issues that maybe causing the problem or has any advice on how best to troubleshoot the issue to prove either way if the firewall's are actually what's causing the issue. Any help would be much appreciated.

 

Thanks in advance,

 

Sean

 

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors