Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HTA-IT
New Contributor

What is the correct process to stop and start a site-to-site VPN tunnel?

I am setting up a new FG200F.  Running the current recommended firmware 7.2.7.  I have discovered a problem with setting up some VPN tunnels to remote sites.  I know all the settings work and are correct as I am mirroring an existing old firewall that is going to be replaced by the new FG200F.

Once the site-to-site VPN tunnel is configured the only way I can get the connection to start working is by rebooting the FG200F.  This does not seem right to me and my concern is if the VPN tunnel was to drop for any reason currently I would have to reboot the Fortinet.  This is not acceptable for me.  Is there some configure I am missing that allows me to restart the FG200 VPN tunnels with the need to reboot the entire appliance?  What is the correct procedure for bringing site-to-site VPN tunnels up and restarting them when required?

4 REPLIES 4
spoojary
Staff
Staff

You can flush the tunnel and bring back the tunnel up via the phase 2 selectors.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-flush-a-VPN-tunnel/ta-p/196631

Siddhanth Poojary
Toshi_Esumi
SuperUser
SuperUser

I think something is wrong with the config on the current 200F/v7.2.7 with the other end of the tunnel. You didn't mention about the old firewall or the other end. I'm assuming either of them is not a FGT.
So please share us the IPsec configuration at least on the FGT side, especially under "config vpn ipsec phase1-interface" and "config vpn ipsec phase2-interface".


Then you need to run IKE debug while it doesn't come up and share us what's in the debug output.
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPNs-tunnels/ta-p/195955

Toshi

ezhupa
Staff
Staff

Hello, 

 

You could try to flush the VPN with the below command: 
diagnose vpn ike gateway clear name <my-phase1-name>

 

 

bkrishnan
Staff
Staff

The below document might help with the procedure to bring the tunnel down/up from the GUI and CLI;
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-bring-the-IPsec-tunnel-down-from-th...

And also collect the debug as Toshi_Esumi suggested while performing the steps.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors