Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Gypsy_Dave
New Contributor III

Site-to-site VPN disconnecting problems. DDNS on one end.

Hi all,

I've seen many posts about this but cant find an answer. I have an HQ with a FG80E and a branch office with a FG30E. I've created a site to site VPN. The HQ used a fixed IP public address and the branch used DDNS. The VPN was working for about a day and now it's gone down. The only way I can get it back online is to reboot the FG30E. This happens every so often.  DDNS always resolves correctly.

 

I've ran the debug on the HQ site and the debug is attached in the text document. 

 

thanks,

 

 

 

6 REPLIES 6
Toshi_Esumi
SuperUser
SuperUser

Probably you need to open a TT at TAC to get this taken a look at. But my concern in the IKE debug log is:

"remote port change 23336 -> 23422"

every time after PSK was confirmed. I'm wondering if there is a NAT device in-between and swtiching/translating the  port after a while. If the 30E is NOT getting the dynamic public IP, use aggressive mode, which doesn't require DDNS.

Gypsy_Dave

Between the FG30E and internet there is a cable router. Could this be the problem? I setup the branch office side as NAT in between VPN connection. Is this correct if there is something between the FG and the internet connection?

Thanks,

Toshi_Esumi

My question was if the 30E gets the public IP from the Cable co. Or just get a private IP like 192.168.0.x from the cable router.

Gypsy_Dave

The cable company provides a dynamic external IP. I'm using Synology's DDNS service. The cable router connects to the Fortigate 30E via an internal IP which is static.

 

Internet (dynamic external IP)=>Cable Router(static internal IP)=>FG30E=>LAN

 

 

Toshi_Esumi

Then again I recommend you configure agressive mode.

Gypsy_Dave

Sorry for the late reply. Thanks, adding the aggressive mode to both sides and also using Fortinet's DDNS instead of Synology's seemed to fix the problem. 

Regards,

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors