60F IPSec site to site AWS NAT no ping
Where is the problem? tunnel up no ping



Where is the problem? tunnel up no ping



Hi robert44,
Thank you for reaching out. I believe the issue here is about phase2 selectors missing the ippool external ip as local address on the fortigate side and would be a remote on the AWS server. This is because you are natting the traffic on the outgoing firewall policy and I see the ping is stopping at the ipsec tunnel. You can further confirm this with running the following debug then start the ping again:
di de flow filter addr 10.100.0.19
di de flow filter proto 1
di de flow show function enable
di de flow trace start 10
di de console time en
di de en
Thank you,
saleha
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.