Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Unable to bring down IPSec VPN Tunnnel

Hi, i' ve configured FG200B as IPSec VPN Dialup Server, clients establish tunnels using FortiClient. but i m unable to bring down the tunnel from IPSec--->Monitor. even though clicking Bring down but still the tunnel is up :( using os 4.2 patch2 any idea??? thanks
15 REPLIES 15
ede_pfau
SuperUser
SuperUser

I bet the tunnel IS torn down but will just re-establish immediately. You should see tunnel-down events in the event log. To prevent automatic tunnel negotiations look at the DPD option in phase 2. Additionally there is a CLI only setting (set auto-negotiate ena) that will re-establish a tunnel immediately. This is documented in the CLI Guide. And finally, the remote side configuration could be responsible for bringing up the tunnel - again, look at the logs.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

thanks, by default auto-negotiate is disable. i tried the DPD option both sides but still unable to terminate the tunnel forcefully. regards, Zeeshan
ede_pfau
SuperUser
SuperUser

I see. Can you somehow prevent the remote user from dialing in? For example, stop him from authenticating. Use PSK plus local user auth. Again, do you see tunnel down events in the log?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

still no luck, i raised a ticket at TAC, they elevated it to L2 support. however i ran and submitted the diag output to them. isn' t there any command to bring down the tunnel? u r rite the tunnels break when i click bring down but soon re-establish.
ede_pfau
SuperUser
SuperUser

diag vpn tunnel flush
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

yeah, used that command. but again tunnel goes up soon
abelio

ORIGINAL: Zeeshan Ahmed yeah, used that command. but again tunnel goes up soon
to avoid guessing, could you post your phase1 and phase2 settings please? (real IPs are not necessary of course)

regards




/ Abel

regards / Abel
rwpatterson
Valued Contributor III

Disable all related policies.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

thats the very last option :(. what if i needed to terminate only one tunnel out of many connected.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors