Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
vhebert
Explorer

Site to Site Tunnel going down randomly

Hi, we have a Site to Site tunnel configuration with a 3rd party (Fortigate).

We are able to bring up the tunnel, but sometimes it will randomly go down, and the only thing I manage to find in the logs is the following : 

 

 

Our public address - Remote public address - 443

IKE Failure : Encryption Failure : No Response from Peer

Action : Reject

(I'll link a screenshot in the post)

 

This Reject happens everytime the tunnel goes down. I don't know why it's trying to use HTTPS in a site-to-site configuration too.

Any ideas ?

Thanks!

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

This seems like a symptom of the VPN going down versus an indication of the actual root cause.

0 Kudos
the_rock
Legend
Legend

Make sure 2 things are enabled on FGT and CP side.

Andy

FGT side:

https://community.fortinet.com/t5/Support-Forum/Keep-Dial-Up-VPN-Tunnel-up-permanently/m-p/78804

 

I know this says dial up, but I believe same applies for ipsec tunnels, can also be enabled in gui under phase 2 settings.

CP side:

global properties -> advanced -> configure -> vpn properties -> keep_ike_sas (make sure this is on) , if not enable it and install policy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events