Use the following diagnose commands to check IPsec phase1/phase2 interface status including the sequence number on the secondary FortiGate. The diagnose debug application ike -1 command is the key to troubleshoot why the IPsec tunnel failed to establish....
Routing NetFlow data over the HA management interface Force HA failover for testing and demonstrations Disabling stateful SCTP inspection Querying autoscale clusters for FortiGate VM Troubleshoot an HA formation FGSP FGSP basic peer setup Synchronizing sessions between FGCP clusters Session ...
Routing NetFlow data over the HA management interface Force HA failover for testing and demonstrations Disabling stateful SCTP inspection Querying autoscale clusters for FortiGate VM Troubleshoot an HA formation FGSP FGSP basic peer setup Synchronizing sessions between FGCP clusters Session ...