Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
damianhlozano
Contributor II

P2P IPsec VPN stop passing traffic

Hello team!!

 

We have 2 Fortigates in 2 different sites: FGT80F in site1, and FGT40F in site2

I had created a P2P IPsec VPN between both Fortigates some time ago (Connected through Internet)

This VPN was working fine for more than 2 years until now.

Recently I realliced that although the VPN was up, I couldnt access to anything in the other site through the VPN.  

Both Fortigates have Firmware 7.6.4

In "Dashboard -> Network -> IPsec", I used the "Bring down -> Entire tunnel" option to "restart" the VPN.

After few seconds, the VPN was up again, and started to work (I started to reach anything in the other site through the VPN)

After some time (less than 2 hours, IDK how much time exactly), happened the same issue and I "solved" this again by "restarting" again the IPsec VPN, using the "Bring down -> Entire tunnel" option.

 

I cant see any related log.

Do you have any suggestion to try to diagnose why did this happen?

We didnt change anything recently.

 

Thanks in advance.

Regards,

Damián

Damián Lozano
Damián Lozano
1 Solution
stmz
New Contributor

Hi ,

Check if your  ipsec phase2 selector is also up when the traffic goes down.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-bring-up-specific-phase-2-selectors...

 

If this is the case you can enable auto-negotiate on phase2 configuration

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Phase1-is-up-yet-phase2-is-down-afte...

 

 

Samet

View solution in original post

Samet
2 REPLIES 2
stmz
New Contributor

Hi ,

Check if your  ipsec phase2 selector is also up when the traffic goes down.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-bring-up-specific-phase-2-selectors...

 

If this is the case you can enable auto-negotiate on phase2 configuration

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Phase1-is-up-yet-phase2-is-down-afte...

 

 

Samet
Samet
damianhlozano

Thank you stmz!!!

It seems that only twice happened, because since the second time I restarted the VPN, this is still working.

I will try this if this happen again!

 

Regards,

Damián

Damián Lozano
Damián Lozano
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors