Hello team!!
I hope you are doing well!!
We have 2 Fortigates 100F in HA with many IPsec VPNs for FortiClient users.
Just one user has a problem to connect from his house. When he use another internet connection in the same computer this works fine but with his own ISP sometime does it fails (Sometimes work also)
When this fails, I can see the following logs on Fortigate:
date=2025-09-11 time=12:38:58 eventtime=1757605138121774900 tz="-0300" logid="0101037134" type="event" subtype="vpn" level="notice" vd="root" logdesc="IPsec phase 1 SA deleted" msg="delete IPsec phase 1 SA" action="delete_phase1_sa" remip=RemoteIP locip=LocalIP remport=18052 locport=4500 outintf="port9" cookies="b77cf798b4edb960/b7f28e5eae0677b7" user="1011" group="N/A" useralt="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="IPsec-IT-W3" fctuid="N/A" advpnsc=0
date=2025-09-11 time=12:38:38 eventtime=1757605118948074500 tz="-0300" logid="0101037127" type="event" subtype="vpn" level="notice" vd="root" logdesc="Progress IPsec phase 1" msg="progress IPsec phase 1" action="negotiate" remip=RemoteIP locip=LocalIP remport=18102 locport=500 outintf="port9" srccountry="Argentina" cookies="b77cf798b4edb960/b7f28e5eae0677b7" user="1011" group="N/A" useralt="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="IPsec-IT-W3" status="success" init="remote" mode="aggressive" dir="outbound" stage=1 role="responder" result="OK" fctuid="N/A" advpnsc=0
date=2025-09-11 time=12:38:38 eventtime=1757605118977300400 tz="-0300" logid="0101037127" type="event" subtype="vpn" level="notice" vd="root" logdesc="Progress IPsec phase 1" msg="progress IPsec phase 1" action="negotiate" remip=RemoteIP locip=LocalIP remport=18102 locport=4500 outintf="port9" srccountry="Argentina" cookies="b77cf798b4edb960/b7f28e5eae0677b7" user="1011" group="N/A" useralt="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="IPsec-IT-W3" status="success" init="remote" mode="aggressive" dir="inbound" stage=2 role="responder" result="DONE" fctuid="N/A" advpnsc=0
date=2025-09-11 time=12:38:38 eventtime=1757605118977889960 tz="-0300" logid="0101037127" type="event" subtype="vpn" level="notice" vd="root" logdesc="Progress IPsec phase 1" msg="progress IPsec phase 1" action="negotiate" remip=RemoteIP locip=LocalIP remport=18052 locport=4500 outintf="port9" srccountry="Argentina" cookies="b77cf798b4edb960/b7f28e5eae0677b7" user="1011" group="N/A" useralt="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="IPsec-IT-W3" status="success" init="local" mode="xauth" dir="outbound" stage=1 role="initiator" result="OK" fctuid="N/A" advpnsc=0
If I ping the Fortigate IP from the computer, I get answers, so this is not a route issue.
I thought maybe this is another issue with his ISP, but I dont think so, because sometimes does this work.
Do you have any idea?
Thanks in advance.
Regards,
Damián
Solved! Go to Solution.
Hi Damian
According to your description I suspect the ISP, even if the issue is intermittent.
You should contact the ISP to ask if there is any limitation or restriction with IPsec.
Hi Damian
According to your description I suspect the ISP, even if the issue is intermittent.
You should contact the ISP to ask if there is any limitation or restriction with IPsec.
Thank you AEK!
There is a cloud EMS providing the settings to clients, but although I know the connection is between each client and the Fortigate (VPN Server), idk if there is any check performed by the EMS, for example, IP reputation. Is this possible?
Does Fortigate or FortiClient EMS checks for IP reputation or something related?
I configured the EMS, so I know this is not a security posture tag, or at least this is not related with the security posture tags that I selected for the VPN (Computers must have an OS not so old, and must have an antivirus updated and running)
Regards,
Damián
Hi Damian
Yes it is possible that your FortiGate is checking IP reputation but this is not the default behavior. It only does it if a policy is configured to do so.
If you have access to the FGT the good thimg to do is to run packet sniffer on FGT while you try connect VPN. If the packets are not reaching FGT the it is definitely due to your ISP.
Thank you AEK!!
We restarted the router of the ISP (Client side) and the issue seems to be solved.
I never suspected of the Fortigates settings, but my boss wanted to be sure before ask anything to the user.
Thanks!
Regards,
Damián
User | Count |
---|---|
2592 | |
1380 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.