Fortinet
FCSS_NST_SE-7.6 · Question #45
Refer to the exhibit. An IPsec VPN tunnel is dropping, as shown by the debug output. Analyzing the debug output, what could be causing the tunnel to go down?
The correct answer is B. Dead Peer Detection is not receiving its acknowledge packet. The continual "notify msg received: R-U-THERE" without any corresponding DPD response causes the FortiGate to delete the IPsec SA when its Dead Peer Detection timer expires, bringing the tunnel down.
Resolve IPsec VPN Issues
Question
Refer to the exhibit. An IPsec VPN tunnel is dropping, as shown by the debug output. Analyzing the debug output, what could be causing the tunnel to go down?
Exhibit
Options
- APhase 2 drops but Phase 1 is up.
- BDead Peer Detection is not receiving its acknowledge packet.
- CThe tunnel drops during rekey negotiation.
- DThe tunnel drops after the timer expires.
How the community answered
(14 responses)- A14% (2)
- B79% (11)
- D7% (1)
Explanation
The continual "notify msg received: R-U-THERE" without any corresponding DPD response causes the FortiGate to delete the IPsec SA when its Dead Peer Detection timer expires, bringing the tunnel down.
Topics
#IPsec VPN#Dead Peer Detection#tunnel drop#IKE debug
Community Discussion
No community discussion yet for this question.
