Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MustphaBassim
New Contributor III

IPsec still up

Hello Dears

 

I have two IPsec tunnels one of them is main and the second is backup sometimes when an issue on main tunnel like phyiscal interface goes down it is not update on Firewall i meant when I go to see the tunnel traffic it is show me the tunnel is up and everything is ok while it must be down because the interface is down so anyone could help me on that ?

 

Best Regards

1 Solution
srajeswaran
Staff
Staff

Please configure DPD , it monitors if the peer is up and then takes the action bring down/up the tunnel.

 

https://community.fortinet.com/t5/FortiClient/Technical-Tip-Configuring-DPD-dead-peer-detection-on-I...

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

View solution in original post

6 REPLIES 6
srajeswaran
Staff
Staff

Please configure DPD , it monitors if the peer is up and then takes the action bring down/up the tunnel.

 

https://community.fortinet.com/t5/FortiClient/Technical-Tip-Configuring-DPD-dead-peer-detection-on-I...

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
MustphaBassim

Thnx dear for reply , in this case we need to enabe DPD with "On Demand" since we have traffic on it always ? is not it ?

srajeswaran

Yeah, "on demand" should be enough.

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
MustphaBassim

thnx for your kind support , one more ask plz is the change of the confiugration on it would impact on IPsec tunnel it is need to be down ?

srajeswaran

If the peer end don't respond to the dpd, it may bring down the tunnel, so I would recommend it enabling during non-peak hours to make sure the impact is minimal (very unlikely).

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
MustphaBassim

Ok dear  thnx for your kind support

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors