Hello Mates,
I am facing this issue with IPSec VPN configured with client end Fortigate firewall. The issue is the phase1 comes up only when I initiate (ping) some traffic to the peer end IP. Even when the user connected to Checkpoint initiating the flow the gateway is not negotiating for either phase1 and/or phase2.
When client forcefully bring phase2 up (in fortigate under vpn monitor section) the phase2 also came up. But even after that the client traffic is getting dropped because of clean up rule even though an existing rule is there for this flow above clean up rule. It seems that rule is invisible for the gateway.
Also, after sometime the tunnel went down.
So to sum up:
1) Gateways not initiating Ipsec negotiation. Only after explicitly initiating the negotiation tunnel comes up.
2) Even when the tunnel is up, the traffic is getting drop by final clean up rule instead of allow rule which is above clean up rule.
Please help on this issue. Thanks.