Hi!
I have one IPsec VPN tunnel (with 2 phase2 subtunnels) to one of our partner. Since few months there have araised problems with this tunnel. Once every now and then (simetimes once per few weeks, and simethimes few times a day) tunnel stop working. Command "diag vpn tunnel list name "tunnel name" show that tunnel is up and ok, but trafic stop flowing. So I'm trying do manually bring it down with commands:
diag vpn tunnel down "name of phase2 tunnel1" "name of phase1 tunnel"
and
diag vpn tunnel down "name of phase2 tunnel2" "name of phase1 tunnel"
and both commands succeds.
Then I'm trying to bring it up with the simmilar commands (the same, but with word "down" replaced by word "up") and then I'm getting error "Command fail. Return code -1". (to complicate matters a little bit, those commands sometimes, but very rare, also succeds, but more often they fails)
Then only way to bring this tunnel back to live (except of restart whole fortigate unit) is modyfing remote gateway IP address to whatever IP, and then restoring back original remote gateway IP.
Could anyone help me to solve this problem?
My ForiGate unit is 100E with ver 6.2.3.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.