Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
patnor
New Contributor

Autokey Keep Alive not working

For one of our customers we want a certain number (3) of IPSec VPN tunnels to remain open, even if there is no traffic going through the tunnel. To accomplish this I enabled the " Autokey Keep Alive" setting in VPN --> IPSEC --> Phase 2 --> Edit VPN Tunnel --> Advanced. This configuration setting does not seem to work. I don' t seem to be able to find out why this is not working. I do notice that when changing the setting from enabled to disabled and vice versa, the FortiGate brings the tunnel up once. Using the ping generator would be a possible solution if you would be able to add more than two src/dst IP' s. Our customer is using a FGT 500A, 2.80, build393. Any help would be greatly appreciated, Patrick.
5 REPLIES 5
Not applicable

Hi, sorry but my English is little There is any problems with the ISP, I recommend you that tou use Nat-traversal, for this you need open UDP: 500 and 4500 to Sites. Your Site-Site is Fortigate-Fortigate? bye
patnor
New Contributor

Aenriquez, our tunnels are from FortiGate to some Nortel device. There is not actually a problem with the tunnels. They come up and transport the traffic. They just go down after timeout expiration and do not automatically come up. To avoid the tunnels going down, we wanted to use the autokey keepalive setting. Patrick
Not applicable

Hi patnor, I admit that the autokey sounds like it should be what you are looking for. But I used the ping generator, works for me like a charm: VPN --> ISEC --> Ping Generator. Hope that helps Stefan
patnor
New Contributor

Stefan, the ping generator indeed works just like we want it to. But you can only use it for 2 tunnels and we have got total of 3 tunnels. Patrick
Not applicable

hello, it seems, that nortel does not support the " keep alive" funktion. are the nortels allowed to reach each other? maybe you can try the" ping generator" to keep alive all the three tunnels. the first ping comes from the forti and goes to nortelA, the second ping comes from nortelB and goes to nortelC. that' s not the best method, but ... regards Andy
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors