Hi all,
We are having a problem with one of our Fortigate 80E firewalls and the IPSec tunnels we have set up to our other locations and for the life of me I can't figure out what is happening. It started when we deployed a new office and rolled out a pair of 80E firewalls. We use IPSec tunnels (not in Interface Mode) to create connections between all of our offices. This has worked for years. However, at this new site we started to notice that some of the tunnels would drop randomly. The issue is that the only way to reconnect them is to delete the tunnel and re-create it. I've tried to re-do the shared key and delete and re-create the phase 2 connector, but only a full recreation of the tunnel will allow it to connect again.
I thought at first it was the firewall, so we replaced them with a brand new pair... but the same thing is happening. It is only happening at this one site and as soon as I recreate it the connection is re-established, so it does not appear to be a connectivity issue with the provider.
I am at a loss... has anyone seen anything similar before?
Hello,
Maybe the issue is related to the ISP and the DPD packets. Since the issue is related to that one branch and a device replacement didn't helped, i would investigate external problems.
If you can, share the VPN event logs for those tunnels and the output of:
diag debug application ike -1
diag debug enable
regards,
tioeudes
At your stage of troubleshooting, I wouldn't rule out anything yet. If it happens quite often, which is easier to troubleshoot, I would run continuous pinging outside of the tunnel at the same time run IKE debugging a little before it's about to drop. IKE debug can run for 30 min. You need to re-set it every 30 min.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1735 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.