Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
create_share
New Contributor

IPSEC Down After Changing the IP Address

Hi,

 

I had an IPsec tunnel working between HO and Branch Fortigates until I changed the WAN IP Address in HO. The branch office Fortigate is behind a Nat Device with a private IP on its WAN Interface. I even recreated the dial-up Tunnel using the wizard but it is not coming up. How can I troubleshoot to resolve this?

 

Thanks.

1 REPLY 1
funkylicious
SuperUser
SuperUser

Hi,

You can start using this, https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Troubleshooting-IPsec-Site-to-Site-T...

 

On the branch, have you enabled NAT-T and set the remote-gw as the new IP of the HO ?
Also, is the HO configured as a dialup server or is it site2site, expecting to match a remote ip/branch ?

 

Also, make sure in the HO that the new IP is reflected in the vpn config, you can do a show full vpn ipsec phase1-interface to see if there's something to change for it.

geek
geek
Labels
Top Kudoed Authors