Several IPsec "tunnel-down" per day :
FGT ===VPN IPsec tunnel=== ISP box (SFR operator) ==fiber access==> Internet
(also many DPD_failure or ESP_error) : reduced by modifying tunnel parameters :
NAT-T = forced, DPD = OnIdle, retry=6, intv=45s
- no way to customize MTU at tunnel level (FGT GUI)
Anyway there are still many "tunnel-down" per day (re-established automatically after:
tunnel up). Many LAN users get network outages (Teams, Outlook etc...)
- ISP box in NAT traversal mode (ESP encapsulated in UDP 4500)
- Many sites are impacted. build = v7.2.11 firmware
Support ticket is opened at SFR operator side (SFR box or backbone ?)
Could it be a known firmware or configuration issue/bug at Fortinat side ?
Thanks
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Thanks,
Hello kerlerom44,
I found this solution. Can you tell me if it helps, please?
Based on the provided context, here are some steps and considerations to address the frequent IPsec tunnel-down issues:
By following these steps, you can systematically troubleshoot and potentially resolve the frequent tunnel-down issues.
Hello Jean-Philippe_P,
Thank you for your reply.
Here is the status on my network/sdwan side :
(issue is still existing)
1. MTU size : I couldn't find the proper CLI commands (seems not available) in order to setup manually MTU at VPN level (or physical interface wan)
2. Quite difficult to find the proper timers but at least with 6/45 dpd_failure has gone
3. I don't have access to the ISP boxes (SFR property) : I guess port-forwarding works because tunnel established initially (unless the NAT-T or table inside ISP box flushes periodically or goes into timeout : who knows ?)
4. I will have a look on the latest official release note of firmware version of 40F/60F; but I'am waiting for a feedback from Fortinet support of my company
5. I'am waiting for a feedback from Fortinet support of my company (already provided some trace)
6. SFR operator : the most difficult part ! An expert Level4 is investigating. So far no root cause identified. (I connected a "witness" Fortigate40F behind an Orange LiveBox and my tunnels are 100% stable since one week ! (but without any trafic from LAN side)).
I'am afraid that the "Grand Public" SFR ISP boxes installed (FTTH access) are not reliable enough to allow endless IPSec tunneling (I might be wrong)
7. Ticket opened also at SFR/Fortinet side
Kind Regards,
User | Count |
---|---|
2567 | |
1358 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.