We have site to site VPN from Fortigate to Cisco. The issue started out with DPD errors with tunnel dropping. We have corrected that issue. The issue we're experiencing now is the tunnel stays up but we aren't able to send traffic to other end and traffic stops flowing. I've noticed this happens between a rekey. This happens every eighteen hours.
We've tried playing with settings by turning off DPD and back on. I increased the lifetime seconds on P2 to 86400 to see if that will alleviate the issue. We're natting a public IP for interesting traffic to their public subnets in P2 selectors. I create a IP pool for that IP that allows everything from my internal network.
Is anyone experiencing the same issue?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If you run IKE debug on the Cisco and FGT at the time the key expired, you should be able to see what failed.
But when we were using Cisco/FGT IKEv1 IPsec years ago we had some problem with DPD between them. So we disabled DPD and used IP SLA from the cisco side to keep the tunnel up. After migrated to IKEv2 DPD(INFORMATIONAL exchange) doesn't seem to cause problems so we're enabling it.
Also, I would suggest disabling anti-replay feature on both sides to see if it makes any difference in the debugging.
I've mentioned disabling anti-replay but haven't heard anything back. We don't maintain the Cisco on the other end.
Under P2 selectors I'm using named addresses that I've specified in FGT and remote end is using IP's. Would that make a difference?
Way back in the past it did. Not sure if it would now. I was on 4.x firmware.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Named selectors vs subnet only matters, in my experience, when there are multiple subnets involved. If one side is combining everything into a single phase two and the other is using multiple phase twos then you are going to run into issues.
We are talking about multiple subnets.
Then it's likely the named selector is combing everything into 1 phase two and the cisco side has a phase 2 per subnet <> subnet.
You'll have to do multiple phase 2's
Worst case, flip one and see if conditions improve.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
If I make changes like that during production times, will it take the tunnel down?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.