As was foretold, we've added advertisements to the forums! If you have questions, or if you encounter any bugs, please visit this thread: https://forums.penny-arcade.com/discussion/240191/forum-advertisement-faq-and-reports-thread/

[sysadmin] on-call schedule - Always you

13»

Posts

  • InfidelInfidel Heretic Registered User regular
    That_Guy wrote: »
    Infidel wrote: »
    That_Guy wrote: »
    What do you have the IPsec tunnel timeout set to?

    Uh keepalive frequency 10, key lifetime 86400 phase 1 / 43200 phase 2?

    The phase 2 selector is setup at a /16 for these servers so it's weird that one host works but the adjacent one doesn't... which is making me think this probably isn't Fortigate stuff at all really? Hmmmm. Maybe it's just the host networking being fubar? But then a little weird that a Fortigate reboot helps.

    Does the link status actually show "up" on both ends of the tunnel? I'm also wondering if you are using Forticloud and/or if you can access both firewalls remotely via wan when you're having the vpn traffic issue. I'm no expert but I'm happy to compare your settings to mine. I may be able to ping some experts on my team that can answer specific questions.

    Yep, would all show up and work for other hosts over the same tunnel.

    OrokosPA.png
  • That_GuyThat_Guy I don't wanna be that guy Registered User regular
    Infidel wrote: »
    That_Guy wrote: »
    Infidel wrote: »
    That_Guy wrote: »
    What do you have the IPsec tunnel timeout set to?

    Uh keepalive frequency 10, key lifetime 86400 phase 1 / 43200 phase 2?

    The phase 2 selector is setup at a /16 for these servers so it's weird that one host works but the adjacent one doesn't... which is making me think this probably isn't Fortigate stuff at all really? Hmmmm. Maybe it's just the host networking being fubar? But then a little weird that a Fortigate reboot helps.

    Does the link status actually show "up" on both ends of the tunnel? I'm also wondering if you are using Forticloud and/or if you can access both firewalls remotely via wan when you're having the vpn traffic issue. I'm no expert but I'm happy to compare your settings to mine. I may be able to ping some experts on my team that can answer specific questions.

    Yep, would all show up and work for other hosts over the same tunnel.

    I reread the original post a couple of times and did some pondering. Stupid question. Could you have anything on the 2.X network that could be using/broadcasting 1.2? Like maybe a rogue statistically assigned device?

    steam_sig.png
  • InfidelInfidel Heretic Registered User regular
    That_Guy wrote: »
    Infidel wrote: »
    That_Guy wrote: »
    Infidel wrote: »
    That_Guy wrote: »
    What do you have the IPsec tunnel timeout set to?

    Uh keepalive frequency 10, key lifetime 86400 phase 1 / 43200 phase 2?

    The phase 2 selector is setup at a /16 for these servers so it's weird that one host works but the adjacent one doesn't... which is making me think this probably isn't Fortigate stuff at all really? Hmmmm. Maybe it's just the host networking being fubar? But then a little weird that a Fortigate reboot helps.

    Does the link status actually show "up" on both ends of the tunnel? I'm also wondering if you are using Forticloud and/or if you can access both firewalls remotely via wan when you're having the vpn traffic issue. I'm no expert but I'm happy to compare your settings to mine. I may be able to ping some experts on my team that can answer specific questions.

    Yep, would all show up and work for other hosts over the same tunnel.

    I reread the original post a couple of times and did some pondering. Stupid question. Could you have anything on the 2.X network that could be using/broadcasting 1.2? Like maybe a rogue statistically assigned device?

    They're all statically assigned, by me, on these networks. Don't see anything else that could be on it but maybe it's a device blackhole due to ARP caching or similar getting goofed up and I'm not resetting the right devices. Gonna find a time to restart the destination device and network.

    OrokosPA.png
  • wunderbarwunderbar What Have I Done? Registered User regular
    Sigh. You silly americans and your weird Thursday holiday. Just realized the vendor I'm waiting to hear from probably won't be getting back to me until Monday.

    XBL: thewunderbar PSN: thewunderbar NNID: thewunderbar Steam: wunderbar87 Twitter: wunderbar
  • That_GuyThat_Guy I don't wanna be that guy Registered User regular
    A lot of our clients take the whole week off.

    steam_sig.png
Sign In or Register to comment.