- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Site to Site Tunnel going down randomly
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Site to Site Tunnel going down randomly
Hi, we have a Site to Site tunnel configuration with a 3rd party (Fortigate).
We are able to bring up the tunnel, but sometimes it will randomly go down, and the only thing I manage to find in the logs is the following :
Our public address - Remote public address - 443
IKE Failure : Encryption Failure : No Response from Peer
Action : Reject
(I'll link a screenshot in the post)
This Reject happens everytime the tunnel goes down. I don't know why it's trying to use HTTPS in a site-to-site configuration too.
Any ideas ?
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This seems like a symptom of the VPN going down versus an indication of the actual root cause.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Make sure 2 things are enabled on FGT and CP side.
Andy
FGT side:
https://community.fortinet.com/t5/Support-Forum/Keep-Dial-Up-VPN-Tunnel-up-permanently/m-p/78804
I know this says dial up, but I believe same applies for ipsec tunnels, can also be enabled in gui under phase 2 settings.
CP side:
global properties -> advanced -> configure -> vpn properties -> keep_ike_sas (make sure this is on) , if not enable it and install policy
