Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
toddp
New Contributor

Phase 2 issue

I have a Fortigate 200b VPN that works fine manually but doesn' t always negotiate properly and frequently gets stuck. If I do some packet sniffing I can see that phase 1 always connects but neither end sends packets when the VPN is stuck. All other VPNs work seamlessly on this firewall. At the destination end I have to assume it is all ok. There are no timeout issues. I have tried keepalive, dpd, rebuild etc
4 REPLIES 4
rwpatterson
Valued Contributor III

Have you tried " set auto-negotiate enable" on the phase2 setting?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Matthijs
New Contributor II

Have you seen the release notes of 4.2.10? ;)
toddp
New Contributor

auto-negotiation works well thanks but I am keeping the VPN active for very little activity. I will continue investigating.
rwpatterson
Valued Contributor III

Little activity = little traffic. I wouldn' t sweat the small stuff. Besides, your policies should keep any errant traffic off the tunnel.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Labels
Top Kudoed Authors