AnsweredHot!Log/Counter For VPN Tunnel Down?

Author
BK_LGW
New Member
  • Total Posts : 15
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/06/14 10:39:09
  • Status: offline
2020/06/15 16:23:01 (permalink)
0

Log/Counter For VPN Tunnel Down?

Hello all. A lot of remote access IPsec clients see random phase2 down messages. I was wondering how do i go about getting to the root cause of each phase2 down instance? I'd like to know if it was just due to DPD deciding FGT can't see the client for a period of time so it yanks the tunnel down or whatever else might cause it. Usually when DPD's the culprit, I see log messages about it prior to the phase2 down message. Can anyone point me in the right direction? 
#1
sw2090
Platinum Member
  • Total Posts : 678
  • Scores: 42
  • Reward points: 0
  • Joined: 2017/06/14 01:27:25
  • Location: Regensburg
  • Status: offline
Re: Log/Counter For VPN Tunnel Down? 2020/06/16 00:15:14 (permalink) ☼ Best Answerby BK_LGW 2020/07/06 08:06:35
0
if you happen to have some FOrtinet logging device connected to your FGT you could look into vpn event log there.
Works fine here on our FortiManager.
If not you could only look at ipsec debug log on cli instead as I don't think that this is in standard event log.
Correction: you see it on the FGT in the Log&Report menue under vpn events.
post edited by sw2090 - 2020/06/16 00:17:58
#2
BK_LGW
New Member
  • Total Posts : 15
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/06/14 10:39:09
  • Status: offline
Re: Log/Counter For VPN Tunnel Down? 2020/06/16 04:34:23 (permalink)
0
Thank you for your reply. We do currently use FortiManager and that's where I can see that P2 message. However there are instances where the P2 goes down with no warning and no additional messages to explain why it happened. That's what I wanna get to the bottom of.
#3
emnoc
Expert Member
  • Total Posts : 5732
  • Scores: 371
  • Reward points: 0
  • Joined: 2008/03/20 13:30:33
  • Location: AUSTIN TX AREA
  • Status: offline
Re: Log/Counter For VPN Tunnel Down? 2020/06/16 10:01:23 (permalink) ☄ Helpfulby BK_LGW 2020/06/30 09:24:11
0
I don't think the logs will be useful on telling you why a phase2 went down. Not sure on what you striving to get at. So many factors can determine why a vpn is disconnected, imho
 
Ken Felix
 

PCNSE 
NSE 
StrongSwan  
#4
BK_LGW
New Member
  • Total Posts : 15
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/06/14 10:39:09
  • Status: offline
Re: Log/Counter For VPN Tunnel Down? 2020/06/30 09:23:32 (permalink)
0
I see. Thank you. I've further familiarized myself with the P1 and P2 negotiation process since my last post and now have a better understanding of what either phase needs in order to successfully complete and then remain active. I believe my disconnects were largely due to DPD failures. I wonder if I can use Link Monitors on remote access VPNs. 
#5
Jump to:
© 2020 APG vNext Commercial Version 5.5