Observability
Fortigate Tunnel Interface is showing UP in SolarWinds Platform when it is Down on the device
SolarWinds shows a tunnel interface as Up while the IPsec tunnel is in fact Down.
First published date
Last published date
Overview
SolarWinds Platform Interface page - VPN_NT1 & VPN_NT1_N are showing UP
Fortigate Device Interface - VPN_NT1 & VPN_NT1_N are showing DOWN
Product section
Cause
Reference - What object IDs (OIDs) does NPM poll for interface information
SolarWinds polls the ForitGate device using Interface MIB OIDs. IF-MIB OIDs indicate that Tunnel operating status is UP.
ifName OIDs - 1.3.6.1.2.1.31.1.1.1.1
- Tunnel 7 = Index 20
- Tunnel 8 = Index 21
- Tunnel 9 = Index 22
- Tunnel 10 = Index 23
ifOperStatus OIDs - 1.3.6.1.2.1.2.2.1.8
Index 20, 21, 22, 23 are showing value 1 (UP)
Per Fortinet, IPsec VPN tunnel monitoring cannot be reliably performed using generic interface OIDs from the IF‑MIB. Fortinet provides specific SNMP OIDs (fgVpn | 1.3.6.1.4.1.12356.101.12) designed to reflect the actual operational status of IPsec tunnels, and these are the recommended OIDs for monitoring.
Resolution
Reference -SolarWinds Observability Self-Hosted 2025.4 release notes (See New Features, Enhanced FortiGate and Cisco Firepower firewall support)
SolarWinds has implemented Fortinet OIDs in SolarWinds Platform 2025.4. Consider upgrading to at least 2025.4.
To avoid conflicting signals, you’ll need to ensure that Site-to-Site VPN is selected and remove the Tunnel from Interfaces via List Resources. This will allow you to use Site‑to‑Site VPN page as the source of truth for VPN tunnel “up/down” status and tunnel‑level statistics, while Interfaces page will be used by Interfaces such as LAN ports, which are still reporting accurate IF-MIB values.