Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AlexAlex77
New Contributor

Can I have an alert when a IPSEC is down in Fortigate 80C?

Hello!

I have a fortigate 80c and 60D with an IPSEC VPN .

Is there a way to use the log (or other tool) to send an email alert when the tunnel is down?

I couldn't see anything on the Log & Report tab

3 REPLIES 3
emnoc
Esteemed Contributor III

Did you try to use the cli. 

 

   config alertemail setting

       set IPsec-errors-logs enable

   end

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Toshi_Esumi

Try Email Alert. Although FTNT says it's undocumented service, the default SMTP server setting under System->Settings->Email Service would work. Then you need to configure under Log & Report->Email Alert Setting. There is "IPsec tunnel errors" on/off slide switch under VPN section.

emnoc
Esteemed Contributor III

Make sure your on the most update version I see your on a older model 

 

You should have a alert like the following

 

 

Message meets Alert condition date=2020-11-10 time=10:36:45 devname=NYCWHPL devid=FG100ETK1xxxxx eventtime=1605026205167586533 tz="-0600" logid="0101037128" type="event" subtype="vpn" level="error" vd="root" logdesc="Progress IPsec phase 1" msg="progress IPsec phase 1" action="negotiate" remip=129.213.170.26 locip=xxx.xxx.xxx.2 remport=500 locport=500 outintf="wan2" cookies="f8e26ab551ff16ca/0000000000000000" user="N/A" group="N/A" useralt="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="N/A" status="failure" init="remote" mode="main" dir="inbound" stage=1 role="responder" result="ERROR" 

 

 

Hope that helps

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors