Skip to main content
ITC_Techs
New Member
March 4, 2020
Question

FortiGate

  • March 4, 2020
  • 1 reply
  • 11120 views

We have an IPsec VPN between FortiGate 60E and SonicWall NSA 2600. The VPN is up and active but no traffic is passing across it.

1 reply

Dave_Hall
New Member
March 4, 2020

Is there a route showing up for the tunnel?

ITC_Techs
ITC_TechsAuthor
New Member
March 4, 2020

There is. There is also a policy to allow inbound and outbound traffic

sw2090
SuperUser
SuperUser
March 5, 2020

are you sure the tunnel is up completely? Green in FGT Ipsec Monitor only means that phase1 has come up.

diag vpn tunnel list on cli will show you if is completely up.

If it shows phase2 name somewhere and a "sa=1" behind it it is up.

 

ALso could be something with ike. Look at my "strange ipsec vpn behavior " thread below for further details.