Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Greggor25
New Contributor

VPN Tunnel stays up but not traffic passing from our end

We have site to site VPN from Fortigate to Cisco.  The issue started out with DPD errors with tunnel dropping. We have corrected that issue.  The issue we're experiencing now is the tunnel stays up but we aren't able to send traffic to other end and traffic stops flowing.  I've noticed this happens between a rekey. This happens every eighteen hours. 

 

We've tried playing with settings by turning off DPD and back on.  I increased the lifetime seconds on P2 to 86400 to see if that will alleviate the issue.  We're natting a public IP for interesting traffic to their public subnets in P2 selectors.  I create a IP pool for that IP that allows everything from my internal network.  

 

Is anyone experiencing the same issue? 

13 REPLIES 13
Greggor25

I made the changes to Phase 2 selectors to be IP addresses.  I'll wait to see if the tunnel drops. 

Greggor25

It dropped again.  I'm at a loss at everything I've tried. 

rwpatterson
Valued Contributor III

Find out from the remote end what their lifetime settings are and match them.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Greggor25

The lifetime settings match on both ends.  We finally were able to get our MPLS circuit fixed so I cut over all the traffic to that circuit and everything is working fine.  For the time being I will leave the VPN for failover. 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors