S2S many tunnels cannot be established at the same time
Confirmed 7/20/2026
Problem
S2S many tunnels cannot be established at the same time
Symptoms
one S2S tunnel is up while others go down.
Environment
FortiGate
FortiOS version
All Versions
Solution
When many S2S IPSEC Tunnels connect to the core FortiGate at the Same time, many points must be taken into consideration:
If the Branch Firewall does not have a static public ip, the tunnel must be configured as Dial-UP on the Core Firewall as the ip of Branch Site changes regularly
If Many Dial-UP Tunnels must be created at the same time it is imortant to set a specific peer ID for every tunnel as an authentication Method. Peer ID must be unique for every Tunne.
In phase 2 Selectors it is important to set at least either Local or Remote Subnets, better both of them, do not leave them on the Default 0.0.0.0/0 otherwise only one tunnel will be able to connect and all other tunnels will drop as one tunnel reserved the default route 0.0.0.0/0
Tags
No tags yet.
Community rating
— / 5 (0)