Third in a series of posts on nat traversal ipsec tunnels. So far the faults have been port forwarding errors on my part; here' s the previous installment. Six tunnels are working. All are via 3G nat-t. Two in particular have a tendency to randomly fail and not recover (however they also run for days at a time). These two are geographically " related" (rural area, tens of km). Their failure isn' t the problem if only they would restore. Getting these two to restore automatically is the question. This kludge works: the simplest way I know to fix a broken tunnel is to edit the remote psk to a known bad value, wait a minute then restore the psk to the correct value. Bingo, the tunnel comes up immediately and ospf is established. All is well until the next failure. Discovered by accident, it' s hardly a good way to fix it. It raises the question what is wrong and why does this work? I have tried to use
diag vpn ike gateway clearWhen the commands are executed at the remote this is not effective. Using
diag vpn tunnel reset
diag ike gateway listI see that the reset commands do something, but obviously not enough. Also diag vpn ike gateway clear ph1-name returns code -61 (4.3.12) even though autocomplete says the syntax is correct? There are firmware mismatches (urg, the bane of my existence) but I doubt this is the issue. However the central is 4 MR1 so doesn' t have the same diags. I don' t want to reset all tunnels here. Any thoughts?
diag vpn tunnel list
to achieve the same thing without the above hack, try the following at the remote end
diag vpn ike restart
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.