- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPsec tunnel shows tunnel is down
i setup 2 IPsec tunnel with counterpart at AWS. the tunnel is working fine but there are 2 separate links showing that the tunnel is down.
how do i remove the unwanted tunnel.
phase2 selector route is down.
or shall i do i reset to bring up the tunnel.
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @yeowkm99 ,
You may run ike debug to check what happened.
ref- https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPNs-tunnels/ta-p/195955
APAC TAC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @yeowkm99 ,
Do you have two phase 2 configurations in the ipsec configuration? If you say yes, you can remove the second phase 2 configuration from the tunnel configuration. Or if you want to bring up this second phase 2 network, you need to add this network on the remote side also.
If it possible, can you share the ipsec phase 2 configuration with us?
NSE 4-5-6-7 OT Sec - ENT FW
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @yeowkm99 ,
Are they both Fortigate firewalls?
Try checking both end if the phase2 selector matches first.
regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @yeowkm99 ,
You may run ike debug to check what happened.
ref- https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPNs-tunnels/ta-p/195955
APAC TAC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @yeowkm99 ,
Please check command result below.
# diag debug console timestamp enable
# diag debug application ike -1
# diag debug enable
Regards,
Jiyong
