- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPsec still up
Hello Dears
I have two IPsec tunnels one of them is main and the second is backup sometimes when an issue on main tunnel like phyiscal interface goes down it is not update on Firewall i meant when I go to see the tunnel traffic it is show me the tunnel is up and everything is ok while it must be down because the interface is down so anyone could help me on that ?
Best Regards
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please configure DPD , it monitors if the peer is up and then takes the action bring down/up the tunnel.
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please configure DPD , it monitors if the peer is up and then takes the action bring down/up the tunnel.
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thnx dear for reply , in this case we need to enabe DPD with "On Demand" since we have traffic on it always ? is not it ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yeah, "on demand" should be enough.
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thnx for your kind support , one more ask plz is the change of the confiugration on it would impact on IPsec tunnel it is need to be down ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If the peer end don't respond to the dpd, it may bring down the tunnel, so I would recommend it enabling during non-peak hours to make sure the impact is minimal (very unlikely).
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ok dear thnx for your kind support
