Skip to main content
Lucas1
Explorer II
August 8, 2024
Solved

Execute Backup does not reach a remote site connected by ipsec.

  • August 8, 2024
  • 4 replies
  • 2129 views

I am having a problem running an automation to backup my computer. I want to send the backup to a sftp server of a remote branch, connected to the fortigate equipment from which I make the backup, and it is as if it did not arrive. If I do a ping it arrives, but I have to specify the source. Does anyone have any idea how I can fix it?

The traffic and routes are allowed on both sides. But when I launch the "execute backup" it doesn't arrive. When pinging I have to add the source option to allow the traffic.

 

Packet Trace #7,2024/08/06 15:59:27,"vd-root:0 received a packet(proto=6, 181.14.198.42:6817->10.1.4.121:22) tun_id=0.0.0.0 from local. flag [S], seq 4203643946, ack 0, win 65535"
Packet Trace #7,2024/08/06 15:59:27,"Find an existing session, id-060b7b91, original direction"
Packet Trace #7,2024/08/06 15:59:27,"enter IPSec interface VPN_IPSec1, tun_id=0.0.0.0"
Packet Trace #7,2024/08/06 15:59:27,output to IPSec tunnel VPN_IPSec1 vrf 0
Packet Trace #7,2024/08/06 15:59:27,"No matching IPsec selector, drop"

Best answer by jguerra

Hi Lucas, sometimes is necessary to configure an IP address in the Ipsec tunnel interfaces for this configuration to work. See the KB below:

 

Technical Tip: Configure automation backup over IPsec tunnel 

4 replies

patelr
Staff
Staff
August 8, 2024

Hello @Lucas1

 

Please review https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPN-tunnel-errors-due-to-traffic-not/ta-p/204584 as your debug says "No matching IPsec selector, drop" , which mean phase-2 configurations aren't matching on both sides. Make sure, all phase-2 configurations should be matched on Local, and remote firewall device.

 

Thanks, 

Ronak Patel

jguerra
Staff
jguerraAnswer
Staff
August 8, 2024

Hi Lucas, sometimes is necessary to configure an IP address in the Ipsec tunnel interfaces for this configuration to work. See the KB below:

 

Technical Tip: Configure automation backup over IPsec tunnel 

Lucas1
Lucas1Author
Explorer II
August 8, 2024

Excellent. This is the answer I was looking for. I will give it a try and see how it goes. Thank you very much.

Umer221
Staff
Staff
August 8, 2024

Hi Lucas,

 

If the Backup server is hosted across the IPsec Tunnel, then you will need to define a source IP address on the FortiGate from where the backup is being initiated. Here is an article that would provide further details regardless of the backup services vendor:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Auvik-backup-fails-while-Auvik-server-across/ta-p/319562

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.