Recientemente configuré un FG60C para una localidad remota (bien remota), para que se conecte via VPN IPSec a un FG620B.
Antes de enviar el equipo a la localidad el VPN funcionó bien, cuando se conectó allá funcionó bien, pero hubo un momento cómo que perdió la conexión, por un apagón electrico. Hoy cuando lo iniciaron el equipo, la VPN no subio, por ende no tengo conexión.
Al hacer un debug app ike -1, veo que hay algun tipo de negociación, pero la VPN no ha subio en el día completo, más de 5 horas, qué podría ser??? Será que el internet del sitio remoto es muy inestable??
El sitio remoto tiene configurado el vpn con static IP del sitio principal, el sitio principal está en modo dial up.
Aquí el debug log (uso en ambos equipos FortiOS 4 MR3 Parch 12.)
Código: Seleccionar todo
HA1 (root) # ike 0:vpnSD-R:17432: negotiation timeout, deleting
ike 0:vpnSD-R: connection expiring due to phase1 down
ike 0:vpnSD-R: deleting
ike 0:vpnSD-R: flushing
ike 0:vpnSD-R: sending SNMP tunnel DOWN trap
ike 0:vpnSD-R: flushed
ike 0:vpnSD-R: deleted
ike 0: comes 186.6.219.103:500->190.80.144.213:500,ifindex=3....
ike 0: IKEv1 exchange=Identity Protection id=524823bc39d43441/0000000000000000 len=276
ike 0: in 524823BC39D434410000000000000000011002000000000000000110E000014AFCAD71368A1F1C96B8696FC77570100000000148299031757A36082C6A621DE00040290
ike 0:Dial-In VPN:17433: responder: main mode get 1st message...
ike 0:Dial-In VPN:17433: VID RFC 3947 4A131C81070358455C5728F20E95452F
ike 0:Dial-In VPN:17433: VID draft-ietf-ipsec-nat-t-ike-03 75310CA6F2C179D9215529D56
ike 0:Dial-In VPN:17433: VID draft-ietf-ipsec-nat-t-ike-02 CD60464CFDB2FC68B6A448
ike 0:Dial-In VPN:17433: VID draft-ietf-ipsec-nat-t-ike-02\n 90CB80913EBB696E5EC427B1F
ike 0:Dial-In VPN:17433: VID draft-ietf-ipsec-nat-t-ike-01 16F6CA16E4A40660AEAA862
ike 0:Dial-In VPN:17433: VID draft-ietf-ipsec-nat-t-ike-00 448515BCD0BE8A8469579DDCC
ike 0:Dial-In VPN:17433: VID DPD AFCAD71368A1F1C96B8696FC77570100
ike 0:Dial-In VPN:17433: DPD negotiated
ike 0:Dial-In VPN:17433: VID FORTIGATE 8299031757A321DE00040290
ike 0:Dial-In VPN:17433: peer is FortiGate/FortiOS (v4 b656)
ike 0:vpnSD-R:17433: negotiation result
ike 0:vpnSD-R:17433: proposal id = 1:
ike 0:vpnSD-R:17433: protocol id = ISAKMP:
ike 0:vpnSD-R:17433: trans_id = KEY_IKE.
ike 0:vpnSD-R:17433: encapsulation = IKE/none
ike 0:vpnSD-R:17433: type=OAKLEY_ENCRYPT_ALG, val=3DES_CBC.
ike 0:vpnSD-R:17433: type=OAKLEY_HASH_ALG, val=SHA.
ike 0:vpnSD-R:17433: type=AUTH_METHOD, val=PRESHARED_KEY.
ike 0:vpnSD-R:17433: type=OAKLEY_GROUP, val=1536.
ike 0:vpnSD-R:17433: ISKAMP SA lifetime=28800
ike 0:vpnSD-R:17433: selected NAT-T version: RFC 3947
ike 0:vpnSD-R:17433: cookie 524823bc39d43441/a7874b8c842b0084
ike 0:vpnSD-R:17433: out 524823BC39D43441A7874B8C842B0084011002005728F20E95452F0D000014AFCAD71368A1F1C96B8696FC77570100000000148299031757A36082C6A621DE00040290
ike 0:vpnSD-R:17433: sent IKE msg (ident_r1send): 190.80.144.213:500->186.6.219.103:500, len=140, id=524823bc39d43441/a7874b8c842b0084
ike 0: comes 186.6.219.103:500->190.80.144.213:500,ifindex=3....
ike 0: IKEv1 exchange=Identity Protection id=524823bc39d43441/0000000000000000 len=276
ike 0: in 524823BC39D4344100000000000000005529D560D000014CD60464335DF21F87CFDB2FC68B6A4480D00001490CB80913EBB696E086381B5EC427B1F0D00001416F6CA16E4A4066D83821A0F0AEAA8620D0000144485152D18B6BB0148299031757A36082C6A621DE00040290
ike 0:vpnSD-R:17433: retransmission, re-send last message
ike 0:vpnSD-R:17433: out 524823BC39D43441A7874B8C842B0084011002000052F0D000014AFCAD71368A1F1C96B8696FC77570100000000148299031757A36082C6A621DE00040290
ike 0:vpnSD-R:17433: sent IKE msg (retransmit): 190.80.144.213:500->186.6.219.103:500, len=140, id=524823bc39d43441/a7874b8c842b0084
ike 0:vpnSD-R:17433: out 524823BC39D43441A7874B8C842B008401100200000000000000008C81070358455C5728F20E95452F0D000014AFCAD71368A1F1C96B8696FC77570100000000148299031757A36082C6A621DE00040290
ike 0:vpnSD-R:17433: sent IKE msg (P1_RETRANSMIT): 190.80.144.213:500->186.6.219.103:500, len=140, id=524823bc39d43441/a7874b8c842b0084
ike 0: comes 186.6.219.103:500->190.80.144.213:500,ifindex=3....
ike 0: IKEv1 exchange=Identity Protection id=524823bc39d43441/0000000000000000 len=276
ike 0: in 524823BC39D4344100000000000000000110020000000000000001140D00005800000001000000010000004C010100020300002001010000800B0001800C7080800100058003000180020002800400050000002402010000800B0001800C7080800C68B6A4480D00001490CB80913EBB696E086381B5EC427B1F0D00001416F6CA16E4A4066D83821A0F0AEAA8620D0000144485152D18B6BBCD0BE8A8469579DDCC0D000014AFCAD71368A1F1C96B8696FC77570100000000148299031757A36082C6A621DE00040290
ike 0:vpnSD-R:17433: retransmission, re-send last message
ike 0:vpnSD-R:17433: out 524823BC39100200000000000000008C0D000034000000010000000000002001010000800B0001800C7080800100058003000180020002800400050D0000144A131C81070358455C5728F20E95452F0D000014AFCAD71368A1F1C96B8696FC7757A36082C6A621DE00040290
ike 0:vpnSD-R:17433: sent IKE msg (retransmit): 190.80.144.213:500->186.6.219.103:500, len=140, id=524823bc39d43441/a7874b8c842b0084
ike 0:vpnSD-R:17433: out 524823BC39D43441A7874B8C842B008401100200000000000010000000100000028010100010000002000800100058003000180020002800400050D0000144A131C81070358455C5728F20E95452F014AFCAD71368A1F1C96B8696FC77570100000C6A621DE00040290
ike 0:vpnSD-R:17433: sent IKE msg (P1_RETRANSMIT): 190.80.144.213:500->186.6.219.103:500, len=140, id=524823bc39d43441/a7874b8c842b0084