Must be something between the fortigate and the remote device, since i've tried settings up a second tunnel for testing purpose. With the same settings between two fortigate devices. This worked from the moment i activated the tunnel.
So i'll try your advice and disabled the dpd check.
I know the remote device is not a Fortigate, but i'll see i can get some more information soon.
Main Topics
Browse All Topics





by: dpk_walPosted on 2008-02-10 at 18:42:53ID: 20863677
Although I am not too familiar with Fortigate, I think the remote end is behind a NAT device or is not responding with HELLO or ACK to your device, as a result your device thinks that the remote end is dead and reinitiates the SA.
Looking at the logs, Phase I and Phase II completes; after this, there is no transmit of traffic over the VPN tunnel and your device checks to see of the remote peer is alive (dpd); it send packets does not get any HELLO or ACK and thinks that the remote peer is actually dead, bringing down the negotiated SA.
I would suggest you to get some details about the remote device. Also, if possible to deactivate dpd on fortigate, you might re-enable dpd later.
Thank you.