I am facing Site to site vpn issue since last one week between FortiGate 100F and FGVM00 . VPN tunnel status is up but network connectivity is down. noticed that all the network connectivity and VPN will restore and work few hours if i restart firewall. how to trace the root cause of the issue and fix it permanently.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @Sree ,
First of all, please check whether there are high CPU/Memory usage issue on both FGT devices or not.
If no, please run the following command for a Ping traffic flow:
diag sniffer packet any 'icmp and host x.x.x.x' 4 // x.x.x.x is the IP you want to Ping
If you see the abnormal sniffer packet capture on which FGT, run the debug flow commands on that FGT:
Please apply the x.x.x.x IP as the "addr" filter for the debug flow commands.
Also use the 'diag debug flow' command. The article Troubleshooting Tip: First steps to troubleshoot connectivity problems to or through a FortiGate wit... describe how to troubleshoot connectivity between networks.
Try to isolate the issue, once you do not know what is causing it. By the way, which firmware version are you using?
Firmware: v7.2.7 build1577
Check the link: https://docs.fortinet.com/document/fortigate/7.2.7/fortios-release-notes/236526/known-issues
Search for 852051. You will find the bug 'Unexpected condition in IPsec engine on SoC4 platforms leads to intermittent IPsec VPN operation.'
You should upgrade to version 7.2.10 to eliminate the bug first, then monitor the FGT and confirm if the issue persist or not after the upgrade.
DPadula
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.