IPsec tunnel not stable
Posted: Tue May 11, 2010 2:40 pm
Good day,
I have an IPsec tunnel connecting to a remote Fortigate peer, but after some time the tunnel just stops working. I always have to run this command to flash installed-sa and the tunnel is initiated again with tunnel being restored.
My IPsec statistics are as follows:
I have an IPsec tunnel connecting to a remote Fortigate peer, but after some time the tunnel just stops working. I always have to run this command to flash installed-sa and the tunnel is initiated again with tunnel being restored.
I have had to create a netwatch script to do the above everytime tunnel goes offline as a workaround, but still want to know why the tunnel is so unstable?/ip ipsec installed-sa flush sa-type=all
My IPsec statistics are as follows:
Please help.[admin@Uitkyk Wines] > /ip ipsec statistics print
in-errors: 0
in-buffer-errors: 0
in-header-errors: 0
in-no-states: 3439
in-state-protocol-errors: 0
in-state-mode-errors: 0
in-state-sequence-errors: 143
in-state-expired: 0
in-state-mismatches: 0
in-state-invalid: 45
in-template-mismatches: 0
in-no-policies: 0
in-policy-blocked: 0
in-policy-errors: 0
out-errors: 0
out-bundle-errors: 0
out-bundle-check-errors: 0
out-no-states: 85
out-state-protocol-errors: 0
out-state-mode-errors: 0
out-state-sequence-errors: 0
out-state-expired: 0
out-policy-blocked: 0
out-policy-dead: 0
out-policy-errors: 0