By default a IPSec tunnel will only come on when traffic is passed throughHowever if you enable Auto-Negotiate at both ends it will stay uphttps://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-the-IPSec-auto-negotiate-and-keepalive/ta-p/189536