- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
changes in VPN phase II
If I need to make a change in the VPN phase II, this change must be execute at the same time at both ends of the vpn tunnel otherwise the tunnel go down?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That depends.
If, for example, you add another encryption/MAC pair to the existing one, traffic will continue to flow. If you change the key lifetime the shorter of both will be negotiated and traffic continues.
Usually, you make the changes on the remote side, see the tunnel down or not, and make the changes on the local side. Or, to play safe, enable HTTPS or SSH access on the WAN port of the remote FGT temporarily.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yeah, just setup the new phase 2 for that tunnel on the local side and then setup the mirror image of it on the remote side. then that phase 2 should become active and you can have that traffic flow as well.
Mike Pruett
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That depends.
If, for example, you add another encryption/MAC pair to the existing one, traffic will continue to flow. If you change the key lifetime the shorter of both will be negotiated and traffic continues.
Usually, you make the changes on the remote side, see the tunnel down or not, and make the changes on the local side. Or, to play safe, enable HTTPS or SSH access on the WAN port of the remote FGT temporarily.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In particular I need to add new subnets in the Remote section of Phase II VPN.
Does this operation need to be accomplished at the same time at both ends of the tunnel?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This should be independent of the operating subnets. No downtime should occur because your are not mucking with the already established tunnels.
I just reread what you typed. What do you mean by "the remote section of the phase II VPNs"?
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In IPsec SA (Phase II) | Traffic to be encrypted | Local | Remote
I have to add new subnets in the 'Remote' column.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you are truly adding and not expanding upon the existing, then you are fine.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I only add new subnets.
So can I do this change in two times, local and remote?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yeah, just setup the new phase 2 for that tunnel on the local side and then setup the mirror image of it on the remote side. then that phase 2 should become active and you can have that traffic flow as well.
Mike Pruett
