Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tutek
Contributor

Link monitor status do not work

Hi,

I have in "Automation" configured event "Link Monitor Event" with action email notification, now I have multiple ipsec tunnels with performance sla applied, these tunnel often turn off / tur on but I never get any email notification. Email service is working for sure. How to troubleshoot this?

18 REPLIES 18
Tutek

Hi I have only logs from today morning concerns Network down, I don't know if this is related to ipsec:

Tutek_0-1671100864790.png

For sure I had today ipsec tunnels disconnected.

what command use to list log for ipsec connection down?

funkylicious

You can view from : Log & Report > Events > VPN Events and there identify the IPsec tunnel in question , another option would be from CLI but that's a little too much right now.

---------------------------
geek
---------------------------
---------------------------geek---------------------------
Tutek

I see in log that tunnel disconnects, but don't know why:

Tutek_0-1671103278107.png

 

ESP error like: Received ESP Packet with unknown SPI.

 

 

funkylicious

Well, here it's not really an issue with the IPsec tunnel but rather a phase2 one, so in this case the trigger would not have worked.

You would need to investigate those P2 settings at both ends to match.

---------------------------
geek
---------------------------
---------------------------geek---------------------------
Tutek

they are configured at both ends using fortigate sd-wan vpn wizard, so they are the same.

Tutek
Contributor

how could i manually trigger an event because I have some events in column "last trigger time" but I never get any emails from Fortigate?

gfleming

You could create a stitch that uses a schedule trigger and just set the schedule for a few minutes in the future...

Cheers,
Graham
Tutek
Contributor

How could I do this?

Tutek_0-1671094044038.png

as you can see "Network down event" was triggered today at 4 AM but I didn't get any email notification.

If I do FGT # diagnose log alertmail test

then I get alert mail so email server is configured properly.

gfleming

See here for schedule triggers: https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/453129/schedule-trigger

 

Are you using default notification.fortinet.net SMTP server or another server?

Cheers,
Graham
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors