Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Nemat
New Contributor II

VPN Site to Site tunnel doesn't come up by normal Bring up.

Dears,

Good Morning, Evening, Afternoon. 

we have vpn site to site when it goes down [phase1 & phase2] and we try to ping it up it doesn't goes up until we issue these commands,

 

"diagnose vpn ike restart"

"diagnose vpn ike gateway clear"

 

we phase this behavior in only this vpn other site2site can be bring up normally.

and we do set Auto-negotiate on it.

 

 

3 REPLIES 3
AlexC-FTNT
Staff
Staff

Here is a guide to follow for troubleshooting an ipsec tunnel:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Troubleshooting-IPsec-VPNs/ta-p/195955


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
seshuganesh
Staff
Staff

For bringing IPSEC tunnel, you can follow this article:

https://docs.fortinet.com/document/fortigate/6.4.5/administration-guide/221346/ipsec-monitor#:~:text....

 

If its still not coming up please collect below logs

diag vpn ike log-filter dst-addr4 a.b.c.d (where a.b.c.d is the remote gateway ip)

diag debug application ike -1

diag debug enable

 

Please collect the below logs and share it with us

Nemat
New Contributor II

Dears,

 

Thanks for replay, I really appreciate it.
the vpn is working find right now the problem appears when it goes done.
I will share the logs as soon as it goes done, its a production environment and I can not do that deliberately.

Thanks a gain.