Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kerlerom44
New Contributor

Fortigate 60F/40F IPsec tunnels instability behind an ISP box (with NAT-T)

Several IPsec "tunnel-down" per day :

FGT ===VPN IPsec tunnel=== ISP box (SFR operator) ==fiber access==> Internet

 

(also many DPD_failure or ESP_error) : reduced by modifying tunnel parameters :

NAT-T = forced, DPD = OnIdle, retry=6, intv=45s

- no way to customize MTU at tunnel level (FGT GUI)

Anyway there are still many "tunnel-down" per day (re-established automatically after:

tunnel up). Many LAN users get network outages (Teams, Outlook etc...)

 

- ISP box in NAT traversal mode (ESP encapsulated in UDP 4500)

- Many sites are impacted. build = v7.2.11 firmware

 

Support ticket is opened at SFR operator side (SFR box or backbone ?)

Could it be a known firmware or configuration issue/bug at Fortinat side ?

 

Thanks

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello kerlerom44,

 

I found this solution. Can you tell me if it helps, please?

 

Based on the provided context, here are some steps and considerations to address the frequent IPsec tunnel-down issues:

 

  1. MTU Size: Although you mentioned the inability to customize MTU at the tunnel level via the GUI, you can check and adjust the MTU size using CLI commands. Ensure that the MTU size is appropriate for the overhead introduced by IPsec.

  2. DPD and NAT-T Settings: You have already adjusted the DPD and NAT-T settings. Ensure that these settings are consistent across all devices involved in the VPN connection.

  3. ISP and NAT Traversal: Since the ISP box is in NAT traversal mode, ensure that port forwarding for UDP ports 500 and 4500 is correctly configured on the ISP box.

  4. Firmware Version: You are using firmware version 7.2.11. Check the release notes for this version to see if there are any known issues related to IPsec VPNs. The context provided does not list specific issues for version 7.2.11, but it is worth verifying with the latest release notes or Fortinet support.

  5. Monitoring and Logs: Use the `diagnose vpn tunnel list` command to monitor the tunnel status and gather more detailed logs. This can help identify patterns or specific triggers for the tunnel-down events.

  6. ISP Support: Since a support ticket is open with the ISP, continue to coordinate with them to rule out any issues on their side, such as NAT or backbone problems.

  7. Fortinet Support: If the issue persists, consider escalating the issue with Fortinet support for further analysis, especially if it might be related to a firmware bug or configuration issue.

 

By following these steps, you can systematically troubleshoot and potentially resolve the frequent tunnel-down issues.

Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors