Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
elk84
New Contributor

Could not bring up ipsec vpn tunnel after bringing it down

Hi!

 

I have one IPsec VPN tunnel (with 2 phase2 subtunnels) to one of our partner. Since few months there have araised problems with this tunnel. Once every now and then (simetimes once per few weeks, and simethimes few times a day) tunnel stop working. Command "diag vpn tunnel list name "tunnel name" show that tunnel is up and ok, but trafic stop flowing. So I'm trying do manually bring it down with commands:

diag vpn tunnel down "name of phase2 tunnel1" "name of phase1 tunnel"

and

diag vpn tunnel down "name of phase2 tunnel2" "name of phase1 tunnel"

and both commands succeds.

Then I'm trying to bring it up with the simmilar  commands (the same, but with word "down" replaced by word "up") and then I'm getting error "Command fail. Return code -1". (to complicate matters a little bit, those commands sometimes, but very rare, also succeds, but more often they fails)

Then only way to bring this tunnel back to live (except of restart whole fortigate unit) is modyfing remote gateway IP address to whatever IP, and then restoring back original remote gateway IP. 

 

Could anyone help me to solve this problem?

My ForiGate unit is 100E with ver 6.2.3.

 

 

0 REPLIES 0
Labels
Top Kudoed Authors