I have had many site-to-site IPsec tunnels working fine for several years until I upgraded to FortiOS 7.4.2. Shortly afterward, my tunnels began dropping connections on random Phase 2 connections. I have had to bring down the phases or entire tunnel to get traffic flowing again many times. I opened a ticket with Fortinet and had three technicians working with me at various times but none found a solution.
I finally downgraded to 7.4.1 and all my problems went away. There is obviously a bug in 7.4.2 and I hope Fortinet finds and acknowledges it and fixes it for the next release.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I appear to be seeing the same problem on 7.0.14 on a 90G.
Hi @minheplus ,
What is your error output ? Can you share it here ?
What's the latest on this issue? I keep getting bugged to upgrade to 7.4.3 but that's not happening until the site-to-site ipsec issue is resolved. Running a 200F here.
The bug still exists in 7.4.3 and it is my understanding that it will be fixed in 7.4.4 which should be released in the next couple weeks. This issue has Bug ID 1003830 and a workaround is provided in the release notes. Known issues | FortiGate / FortiOS 7.4.3 | Fortinet Document Library
7.4.4 has been released and it looks as though this issue still has not been resolved. Known issues still seems to state to use the work around.
Just trying to keep this post updated.
Thanks for the update, it's indeed not fixed in 7.4.4
I also updated to 7.4.4 and still have the same problem.
I also updated to 7.4.4 and still have the same problem.
But we have the problem with many other things besides IPSec
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1640 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.