Hi,
We have recently upgraded our firewalls to 7.4.2 and have multiple IPSec tunnels active on firewall, but this one tunnel between FortiGate1 and FortiGate2 firewall, after upgrade, traffic stops flowing via tunnel every 24 hours. the only solution to resume traffic flow is to bounce the tunnel.
we have tried disabling npu-offload, tear-down the entire tunnel and rebuild the tunnel, turned off auto-negotiate for phase2, reduced the phase2 and phase1 key lifetime, nothing resolves the issue except bouncing tunnel each time we encounter the issue.
We have IPsec tunnel running from Fortigate1 to Fortigate3 and FortiGate4 having firmware version 7.4.2, have no issue.
Any idea what could be the issue?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello Sir,
Thank you for contacting the Fortinet support.
First disable the hardware acceleration using the below document and then take the IKE debugs as below:
dia debug reset
dia debug disable
diagnose vpn ike log-filter dst-addr4 <tunnel_public_dst_ip>
diagnose debug application ike -1
diagnose debug console timestamp enable
diagnose debug enable
!
Best Regards,
Piyush Mudgal
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.