Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

IPSec VPN is going down

hi! Some time after bringing up an IPSec VPN, it comes down and I it gets up only when I send data from one side. Is there any way to keep it up permanently? thanks
4 REPLIES 4
rwpatterson
Valued Contributor III

In your phase 1 definition, the advanced section near the bottom is an option " Keep Alive Interval" . Check this. Usually this will keep a tunnel up. I have seen tunnels drop with this on, but it' s better than nothing. Also in phase 2, there is again in the advanced section an " Auto Key Keep Alive" . Check this box as well. In the policy that allows tunnel traffic, the " Allow Inbound" and " Allow Outbound" determine which sides of the tunnel are allowed to begin negotiation to open it. I usually check both, because it' s secure, either side should be able to bring it up. Good luck

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
romanr
Valued Contributor

ORIGINAL: Raquel hi! Some time after bringing up an IPSec VPN, it comes down and I it gets up only when I send data from one side. Is there any way to keep it up permanently? thanks
Have a look into your logs! some configuration erros might lead to the fact, that only one of the Boxes is able to establish the IPSec-tunnel.
Not applicable

Configuration was ok and I didnt see anything wrong in logs (still looking). Thanks for your quick replies If you have any other idea, I will be pleased to hear them
abelio

Raquel, if you want keep up the vpn even when there' s no traffic originated from hosts behind peers, you need put additional CLI commands as rwpatterson suggested above. We don' t know which FortiOS you' re running, and which vpn type you' ve configured. So, let assume fortios 3.0 and VPN policy or tunnel mode: in that case,
 config vpn ipsec phase2
   edit <name_of_your VPN_phase2>
   set auto-negotiate enable
 end
 
If you' re under different fortios/vpn, update that info in the forum, so we can see it hope it helps,

regards




/ Abel

regards / Abel
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors