We have site to site VPN from Fortigate to Cisco. The issue started out with DPD errors with tunnel dropping. We have corrected that issue. The issue we're experiencing now is the tunnel stays up but we aren't able to send traffic to other end and traffic stops flowing. I've noticed this happens between a rekey. This happens every eighteen hours.
We've tried playing with settings by turning off DPD and back on. I increased the lifetime seconds on P2 to 86400 to see if that will alleviate the issue. We're natting a public IP for interesting traffic to their public subnets in P2 selectors. I create a IP pool for that IP that allows everything from my internal network.
Is anyone experiencing the same issue?
I made the changes to Phase 2 selectors to be IP addresses. I'll wait to see if the tunnel drops.
It dropped again. I'm at a loss at everything I've tried.
Find out from the remote end what their lifetime settings are and match them.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
The lifetime settings match on both ends. We finally were able to get our MPLS circuit fixed so I cut over all the traffic to that circuit and everything is working fine. For the time being I will leave the VPN for failover.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.