Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
andybarker
New Contributor II

FortiOS 7.4.2 Bug Causes IPsec VPN Tunnel Phase 2 Instability

I have had many site-to-site IPsec tunnels working fine for several years until I upgraded to FortiOS 7.4.2. Shortly afterward, my tunnels began dropping connections on random Phase 2 connections. I have had to bring down the phases or entire tunnel to get traffic flowing again many times. I opened a ticket with Fortinet and had three technicians working with me at various times but none found a solution.

 

I finally downgraded to 7.4.1 and all my problems went away. There is obviously a bug in 7.4.2 and I hope Fortinet finds and acknowledges it and fixes it for the next release.

63 REPLIES 63
OLiH
New Contributor II

The ticket # is 9166522 downgraded to 7.4.1.

People_First

Currently waiting for support. 7.43 definitely did not fix the IPsec tunnel issue. 

BillH_FTNT

Hi @People_First 

You can consider going to some version to avoid the vulnerability.

Bill

 

OLiH
New Contributor II

Please welcome Orestis from Fortinet. He is stuck because I cannot provide him with logs (forced to downgrade). Maybe someone can provide logs?

OLiH
New Contributor II

 

Orestis suggest that we upgrade and trigger the issue to be able to get logs. I am not keen, we need the tunnels UP. Any volunteer?

 

The next suggestion is to wait for next version.

 

I do not feel like we are getting support, especially since it is not still acknowledged it is a bug......

 

Here is the answer:

    Hello team

I followed up with the suggested link but without logs I cannot open an engineering report or confirm that this is a bug

I believe that you facing a problem but if we cannot investigate further we cannot specify what the issue is

in this case either create a maintenance window and update and provide us the logs to investigate or wait for the next version

Best regards
Orestis

Kangming

Thanks for your feedback. Could you share your configuration file with me? I will try reproducing it and file a bug internally to let Dev investigate the cause.

My email is: kmliu@fortinet.com, you could upload the configuration to the ticket or send it to me directly, thank you so much.

Thanks

Kangming

andybarker
New Contributor II

I cannot spend any more time helping Fortinet Support troubleshoot this issue. I gave them five days of my time and many logs, remote sessions, etc. The first two technicians changed how my IPsec VPNs operated, and the third tech said the changes they made were wrong and needed to be reversed to the original settings. None of the changes they made helped at all.

 

I will be waiting to see if they admit it is a bug and say it is fixed.

Kangming
Staff
Staff

Hi  andybarker,

Can you share the output of this command?

 

#get sys status

 

License Status: Low-Encryption(LENC) ----------------------->

---> FortiOS: 7.4.2

 

If you match this result, may have matched a known bug.

Thanks

Kangming

RepareIT
New Contributor II

I just checked on both of my firewall (200F and 100F), I don't have that License Status line at all. I have the same bug and stuck on 7.4.3 for the vulnerability fixes.

Kangming

Thanks for your feedback. This should be another problem, but there is no internal bug record yet. Can you share your configuration file with me? I will try reproducing it and file a bug internally to let Dev investigate the cause.

My email is: kmliu@fortinet.com, you could upload the configuration to the ticket or send it to me directly, thank you so much.

Thanks

Kangming

Labels
Top Kudoed Authors