Hi all,
I've seen many posts about this but cant find an answer. I have an HQ with a FG80E and a branch office with a FG30E. I've created a site to site VPN. The HQ used a fixed IP public address and the branch used DDNS. The VPN was working for about a day and now it's gone down. The only way I can get it back online is to reboot the FG30E. This happens every so often. DDNS always resolves correctly.
I've ran the debug on the HQ site and the debug is attached in the text document.
thanks,
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Probably you need to open a TT at TAC to get this taken a look at. But my concern in the IKE debug log is:
"remote port change 23336 -> 23422"
every time after PSK was confirmed. I'm wondering if there is a NAT device in-between and swtiching/translating the port after a while. If the 30E is NOT getting the dynamic public IP, use aggressive mode, which doesn't require DDNS.
Between the FG30E and internet there is a cable router. Could this be the problem? I setup the branch office side as NAT in between VPN connection. Is this correct if there is something between the FG and the internet connection?
Thanks,
My question was if the 30E gets the public IP from the Cable co. Or just get a private IP like 192.168.0.x from the cable router.
The cable company provides a dynamic external IP. I'm using Synology's DDNS service. The cable router connects to the Fortigate 30E via an internal IP which is static.
Internet (dynamic external IP)=>Cable Router(static internal IP)=>FG30E=>LAN
Then again I recommend you configure agressive mode.
Sorry for the late reply. Thanks, adding the aggressive mode to both sides and also using Fortinet's DDNS instead of Synology's seemed to fix the problem.
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1643 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.