Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mehar
New Contributor

IPSec VPN reconnect between HO and branch offices (behind router)

Hello all,

 

We are using Fortigate 60e in the Head office and 30e at the branch office. The branch office has a router from the ISP and can not be removed. I have successfully formed a site-to-site tunnel from branch office to HO using the wizards. For the BO i used the 'this site is behind a router' option.

 

VPN connects but over time it disconnects and then doesn't connect back automatically. Is there a way for the BO fortinet to initiate the connection automatically by itself? Is there some sort of a script for this because I didn't see any related settings unless I overlooked them?

2 REPLIES 2
Toshi_Esumi
Esteemed Contributor III

I would recommend you set proper IPs on the tunnel interfaces on both sides, like 10.0.0.1/32 and 10.0.0.2/32 (don't forget to configure "set remote-ip" as well). Then run "link-monitor", which you can find many places how to, on the BO side to ping the HO IP. That would bring up (keep) the tunnel up when path problems are resolved.

ede_pfau
Esteemed Contributor III

Or fix the underlying problem, that is, check the idle timer settings in phase1 and phase2 ("set keepalive"), for IKE/SAs and NAT-Traversal. They must match on both sides. The BO firewall is initiating the tunnel (dial-in), so I suspect it's a NAT-T failure.

Of course, a simple permanent ping will cover that hole as well...but not fix it.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors