Hi,
I have in "Automation" configured event "Link Monitor Event" with action email notification, now I have multiple ipsec tunnels with performance sla applied, these tunnel often turn off / tur on but I never get any email notification. Email service is working for sure. How to troubleshoot this?
Created on ‎12-15-2022 02:41 AM Edited on ‎12-15-2022 02:42 AM
Hi I have only logs from today morning concerns Network down, I don't know if this is related to ipsec:
For sure I had today ipsec tunnels disconnected.
what command use to list log for ipsec connection down?
You can view from : Log & Report > Events > VPN Events and there identify the IPsec tunnel in question , another option would be from CLI but that's a little too much right now.
I see in log that tunnel disconnects, but don't know why:
ESP error like: Received ESP Packet with unknown SPI.
Well, here it's not really an issue with the IPsec tunnel but rather a phase2 one, so in this case the trigger would not have worked.
You would need to investigate those P2 settings at both ends to match.
Created on ‎12-15-2022 04:28 AM Edited on ‎12-15-2022 04:29 AM
they are configured at both ends using fortigate sd-wan vpn wizard, so they are the same.
how could i manually trigger an event because I have some events in column "last trigger time" but I never get any emails from Fortigate?
You could create a stitch that uses a schedule trigger and just set the schedule for a few minutes in the future...
How could I do this?
as you can see "Network down event" was triggered today at 4 AM but I didn't get any email notification.
If I do FGT # diagnose log alertmail test
then I get alert mail so email server is configured properly.
See here for schedule triggers: https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/453129/schedule-trigger
Are you using default notification.fortinet.net SMTP server or another server?
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.