Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Greggor25
New Contributor

VPN Tunnel stays up but not traffic passing from our end

We have site to site VPN from Fortigate to Cisco.  The issue started out with DPD errors with tunnel dropping. We have corrected that issue.  The issue we're experiencing now is the tunnel stays up but we aren't able to send traffic to other end and traffic stops flowing.  I've noticed this happens between a rekey. This happens every eighteen hours. 

 

We've tried playing with settings by turning off DPD and back on.  I increased the lifetime seconds on P2 to 86400 to see if that will alleviate the issue.  We're natting a public IP for interesting traffic to their public subnets in P2 selectors.  I create a IP pool for that IP that allows everything from my internal network.  

 

Is anyone experiencing the same issue? 

13 REPLIES 13
Toshi_Esumi
SuperUser
SuperUser

If you run IKE debug on the Cisco and FGT at the time the key expired, you should be able to see what failed. 

But when we were using Cisco/FGT IKEv1 IPsec years ago we had some problem with DPD between them. So we disabled DPD and used IP SLA from the cisco side to keep the tunnel up. After migrated to IKEv2 DPD(INFORMATIONAL exchange) doesn't seem to cause problems so we're enabling it. 

Also, I would suggest disabling anti-replay feature on both sides to see if it makes any difference in the debugging. 

Greggor25

I've mentioned disabling anti-replay but haven't heard anything back. We don't maintain the Cisco on the other end. 

 

Under P2 selectors I'm using named addresses that I've specified in FGT and remote end is using IP's. Would that make a difference?   

rwpatterson
Valued Contributor III

Way back in the past it did. Not sure if it would now. I was on 4.x firmware.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
brycemd

Named selectors vs subnet only matters, in my experience, when there are multiple subnets involved. If one side is combining everything into a single phase two and the other is using multiple phase twos then you are going to run into issues.

Greggor25

We are talking about multiple subnets.  

brycemd

Then it's likely the named selector is combing everything into 1 phase two and the cisco side has a phase 2 per subnet <> subnet.

 

You'll have to do multiple phase 2's

Greggor25

I have multiple Phase 2 selectors setup.  I'm thinking about changing them back IP address. 

 

Each of them are going to different subnets.  

rwpatterson
Valued Contributor III

Worst case, flip one and see if conditions improve.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Greggor25

If I make changes like that during production times, will it take the tunnel down?  

Labels
Top Kudoed Authors