Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
WDCB
New Contributor

Ipsec Interface down

Hi All - Newbie here

I am looking for a bit of guidance or KB's for how to bring up an Ipsec S2S interface. I have IPSec to Azure an every so often the interface will down. The Wan interface does not miss a beat and there is one other IPSec to a Forti that does not drop so its not failover. I can easily enough bring up the interface again with the IKE reset through CLI, but gui would not work. So I am looking for a way that I can use something like Link monitor to if the interface onthe VPN drop to simply execute a reset on that IPSec interface. I have set the Keep Alive settings, but it still goes down occasionally and requires reboot or manual reset. 

This is not a SD-Wan config, but perhaps it should be ? Issue is it is a single ISP connection with two IPSec on that. 

 

Guidance please or a pointer to a KB will help

 

Thanks in advance

1 REPLY 1
abarushka
Staff
Staff

Hello,

 

I would like to ask whether auto-negotiate is enabled?

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-the-IPSec-auto-negotiate-and-keepali...

FortiGate
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors