Hi all,
We are trying to move an IPsec VPN over from one WAN connection to the other on a FGT100D, with a different ISP and thus a different public address. We reconfigured the VPN both ends, but it won't re-establish. Running diag debug ike -1 shows that the firewall still has the old connection in memory, and tries to continue to use it. When it tries to initiate over the new address, an error is shown:
duplicate connection detected on name insert, dropping this connection
I have seen the messages from ede_pfau about the black hole routing, but I am unsure how to make this work successfully. There's apparently no way to silence the connection attempts, reset the connection, or have it quiet down.
I have tried to disable the policies and disable the routes, both ends, and re-enabling them, but this had hardly any effect.
Reconfiguring the old WAN address and WAN interface specification on both sides of the VPN connection to what it was before re-enables the VPN immediately to its active state.
Any suggestions?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
One thing I'm sure that would work is completely removing the old config then reboot.
In other words likely the sessions still exist. Try clear all session related to the old IPSec.
Thanks Toshi
I have taken your advice, removed the existing definitions related to the ipsec connection via console commands, in reverse order from creation:
[ol]
modified the configuration, and applied these in the normal order:
[ol]
and added a static route for the destination address passing over the secondary WAN port.
It works now.
Thank you
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.