Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
David
New Contributor

VPN IPSEC Monitor

In the IPSEC monitor it shows all VPN tunnels, in the status column there are 2 designations " Bring up" which I take as the tunnel is down and " Bring down" as meaning the tunnel is up. When I see the status as " Bring up" I take that as a problem when in fact the tunnel is connected just idle. Can this be changed, either come up with a 3rd status as Idle or just leave at " Bring down" and only display " Bring up" when the connection is lost. Thanks
5 REPLIES 5
David
New Contributor

I based the statement about the tunnel being idle when the status is " Bring up" because when I called support a few months ago about my tunnels keep going down the tech looked at it and told me they are up just in a idle state. Ok I said and went on my merry way. I just finished talking to support about a Fortimanager issue and brought up the issue about idle VPN tunnels which he had never heard of. He looked at it and concluded that the Phase 2 was the problem, the auto-negotiate is set to disable, which is the default setting. This option is not available through the GUI which is how I setup all my VPN tunnels. The commands are config vpn ipsec phase2-interface Edit " Phase 2 name" set auto-negotiate enable.
vanc
New Contributor II

If you don' t have constant traffic, the tunnel can go idle after the SA expires. For an idle tunnel, you just don' t have a live SA. But once traffic passing through Fortigate, SA will be renegotiated, and traffic can go through again. So the first network connection may get stuck for a couple of seconds. If you have auto-negotiate enabled, SA will always be renegotiated just a dozen seconds before the current SA expires.
rwpatterson
Valued Contributor III

...so the tunnel is still ' idle' , but it' s state is now up!

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
David
New Contributor

Ok so back to my original question, in the status column of the VPN monitor there is no difference between being Idle or a hard down(equipment needs to be rebooted, or tech sent to site) both states will show the same status. Can this be changed. Plus another question, why would you not set the auto-negotiate to enabled is there a reason to leave it disabled?.
rwpatterson
Valued Contributor III

Not all tunnels need to be up 24/7. Some only have activity during working hours, so when traffic starts, the tunnels come up. Then there are some for remote interfaces which need to send/receive traffic all the time but sporadically, so having to wait for the tunnel to be live may incur errors. In health care this is important. Having the tunnels up does add some overhead to the boxes.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Labels
Top Kudoed Authors