Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rosdev
New Contributor

FortiGate 100D/Fortios 5.2.4: DPD and auto-negotiate

Hello everyone,

When DPD is enabled on my FortiGate 100D device and the remote peer has not responded within the DPD timeout interval (governed by dpd-retrycount and dpd-retryinterval settings) , the FortiGate device seems to try to actively re-establish the tunnel.

 

Other posts suggest that this behavior depends on the auto-negotiate setting (available at least for phase 1?) However, an attempt to disable this setting leads to an error:

 

config vpn ipsec phase1-interface

edit "conn-name"

set auto-negotiate disable

 

command parse error before 'auto-negotiate'

Command fail. Return code -61

 

This behavior is not desired in my configuration, since multiple "road-warriors" may be connecting the FortiGate device, i.e. the devices which might disappear and later reappear (probably with a different IP address). So I would prefer the FortiGate to simply clear any SA's related to the tunnel and passively wait for the client device to reconnect. If I disable DPD on the FortiGate altogether, it does respond to R_U_THERE packets from my client devices (which is expected). But once a client device is gone, the stale tunnel is still reported as active. My concern is that this might consume the FortiGate's resources indefinitely.

 

My FortiGate runs with FotiOS 5.2.4, build 668 (GA)).

I will greatly appreciate any suggestions,

Oleg

0 REPLIES 0
Labels
Top Kudoed Authors