Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kerlerom44
New Contributor

Fortigate 60F/40F IPsec tunnels instability behind an ISP box (with NAT-T)

Several IPsec "tunnel-down" per day :

FGT ===VPN IPsec tunnel=== ISP box (SFR operator) ==fiber access==> Internet

 

(also many DPD_failure or ESP_error) : reduced by modifying tunnel parameters :

NAT-T = forced, DPD = OnIdle, retry=6, intv=45s

- no way to customize MTU at tunnel level (FGT GUI)

Anyway there are still many "tunnel-down" per day (re-established automatically after:

tunnel up). Many LAN users get network outages (Teams, Outlook etc...)

 

- ISP box in NAT traversal mode (ESP encapsulated in UDP 4500)

- Many sites are impacted. build = v7.2.11 firmware

 

Support ticket is opened at SFR operator side (SFR box or backbone ?)

Could it be a known firmware or configuration issue/bug at Fortinat side ?

 

Thanks

2 REPLIES 2
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors