- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is the correct process to stop and start a site-to-site VPN tunnel?
I am setting up a new FG200F. Running the current recommended firmware 7.2.7. I have discovered a problem with setting up some VPN tunnels to remote sites. I know all the settings work and are correct as I am mirroring an existing old firewall that is going to be replaced by the new FG200F.
Once the site-to-site VPN tunnel is configured the only way I can get the connection to start working is by rebooting the FG200F. This does not seem right to me and my concern is if the VPN tunnel was to drop for any reason currently I would have to reboot the Fortinet. This is not acceptable for me. Is there some configure I am missing that allows me to restart the FG200 VPN tunnels with the need to reboot the entire appliance? What is the correct procedure for bringing site-to-site VPN tunnels up and restarting them when required?
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can flush the tunnel and bring back the tunnel up via the phase 2 selectors.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-flush-a-VPN-tunnel/ta-p/196631
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think something is wrong with the config on the current 200F/v7.2.7 with the other end of the tunnel. You didn't mention about the old firewall or the other end. I'm assuming either of them is not a FGT.
So please share us the IPsec configuration at least on the FGT side, especially under "config vpn ipsec phase1-interface" and "config vpn ipsec phase2-interface".
Then you need to run IKE debug while it doesn't come up and share us what's in the debug output.
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPNs-tunnels/ta-p/195955
Toshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
You could try to flush the VPN with the below command:
diagnose vpn ike gateway clear name <my-phase1-name>
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The below document might help with the procedure to bring the tunnel down/up from the GUI and CLI;
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-bring-the-IPsec-tunnel-down-from-th...
And also collect the debug as Toshi_Esumi suggested while performing the steps.
