Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
create_share
New Contributor II

IPSEC Down After Changing the IP Address

Hi,

 

I had an IPsec tunnel working between HO and Branch Fortigates until I changed the WAN IP Address in HO. The branch office Fortigate is behind a Nat Device with a private IP on its WAN Interface. I even recreated the dial-up Tunnel using the wizard but it is not coming up. How can I troubleshoot to resolve this?

 

Thanks.

1 REPLY 1
funkylicious
SuperUser
SuperUser

Hi,

You can start using this, https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Troubleshooting-IPsec-Site-to-Site-T...

 

On the branch, have you enabled NAT-T and set the remote-gw as the new IP of the HO ?
Also, is the HO configured as a dialup server or is it site2site, expecting to match a remote ip/branch ?

 

Also, make sure in the HO that the new IP is reflected in the vpn config, you can do a show full vpn ipsec phase1-interface to see if there's something to change for it.

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors