If I need to make a change in the VPN phase II, this change must be execute at the same time at both ends of the vpn tunnel otherwise the tunnel go down?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
That depends.
If, for example, you add another encryption/MAC pair to the existing one, traffic will continue to flow. If you change the key lifetime the shorter of both will be negotiated and traffic continues.
Usually, you make the changes on the remote side, see the tunnel down or not, and make the changes on the local side. Or, to play safe, enable HTTPS or SSH access on the WAN port of the remote FGT temporarily.
yeah, just setup the new phase 2 for that tunnel on the local side and then setup the mirror image of it on the remote side. then that phase 2 should become active and you can have that traffic flow as well.
Mike Pruett
That depends.
If, for example, you add another encryption/MAC pair to the existing one, traffic will continue to flow. If you change the key lifetime the shorter of both will be negotiated and traffic continues.
Usually, you make the changes on the remote side, see the tunnel down or not, and make the changes on the local side. Or, to play safe, enable HTTPS or SSH access on the WAN port of the remote FGT temporarily.
In particular I need to add new subnets in the Remote section of Phase II VPN.
Does this operation need to be accomplished at the same time at both ends of the tunnel?
This should be independent of the operating subnets. No downtime should occur because your are not mucking with the already established tunnels.
I just reread what you typed. What do you mean by "the remote section of the phase II VPNs"?
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
In IPsec SA (Phase II) | Traffic to be encrypted | Local | Remote
I have to add new subnets in the 'Remote' column.
If you are truly adding and not expanding upon the existing, then you are fine.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Yes, I only add new subnets.
So can I do this change in two times, local and remote?
yeah, just setup the new phase 2 for that tunnel on the local side and then setup the mirror image of it on the remote side. then that phase 2 should become active and you can have that traffic flow as well.
Mike Pruett
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.