Skip to main content
FGTnewbie
New Member
March 8, 2016
Question

Adding a second VPN Tunnel with Cisco ASA

  • March 8, 2016
  • 1 reply
  • 16271 views

Hello everyone 

 

Im trying to add a second VPN tunnel to our fortigate. everything seems ok and the tunnel is up but no communication between the two sites. 

 

Trace route on CLi on fortigate just drops 

Traceroute from lan goes to the internet and drops 

 

I used a wizard to create the tunnel. On our side we have Fortigate 200D and the other end is  a Cisco ASA

 

diag gateway list results below 

vd: root/0

name: XXXXXXXXXXXXX

version: 1

interface: port6 15

addr: XXXXXXXXXXXX:500 -> XXXXXXXXXXXXX:500

created: 5038s ago

IKE SA: created 1/1  established 1/1  time 630/630/630 ms

IPsec SA: created 5/85  established 5/5  time 180/358/800 ms

 

  id/spi: 2 e9e783ffee4b81ee/557d82bf62f157f8

  direction: initiator

  status: established 5038-5037s ago = 630ms

  proposal: aes256-sha1

  key: f1cf0d0329195bdc-683d8c0d7660f9ce-af2786dfc8dd072b-310f90e043bc78a9

  lifetime/rekey: 43200/37862

  DPD sent/recv: 00000000/00000000

 

vd: root/0

name: YYYYYYYYYYYYYYYYY

version: 1

interface: port6 15

addr: YYYYYYYYYYYY:500 -> YYYYYYYYYYYYYYYY:500

created: 443s ago

IKE SA: created 1/1  established 1/1  time 670/670/670 ms

IPsec SA: created 1/1  established 1/1  time 890/890/890 ms

 

  id/spi: 16 144ca8e0a32ae987/128dced7496e5590

  direction: initiator

  status: established 443-442s ago = 670ms

  proposal: aes256-sha1

  key: 1ea51db8c63bf1e9-73cc692d2d2fa48f-f14ad0ffe946bccf-6712eab0676207db

  lifetime/rekey: 86400/85657

  DPD sent/recv: 000038d2/00000000

 

Any idea of what i'm doing wrong? 

 

    1 reply

    Nils
    New Member
    March 8, 2016

    Did you create a Policy?

    Can you print the configuration for the tunnel?

    FGTnewbie
    FGTnewbieAuthor
    New Member
    March 8, 2016

    Hi Nissan, 

     

    Thanks for the response. Yes the policy was created. I used the wizard to create the tunnel, then i converted it to a custom tunnel and changed the Phase 1 and phase 2 parameters to match the remote site 

     

    P1

     

    AES256 SHA1  5

     

    AES256 SHA1  2

     

     

     

     

    Nils
    New Member
    March 8, 2016

    Ok, have you defined the local and remote network?