Skip to main content
Fortimaster1
Explorer
January 30, 2026
Question

Fortigate asks about ARP in an IPSEC tunnel?

  • January 30, 2026
  • 1 reply
  • 144 views

Hi all ¡

I have several fortigate IP sec tunnels but one of them is acting strangely. The tunnel is stablished with another fortigate correctly.

 

Internal network 10.10.10.0/24 --> Fortigate 1

Internal network 11.11.11.0/24--> Fortigate 2.

 

I have static routes in both fortigates etc... 

 

If internal network of fortigate 1 sends traffic to internal network of fortigate 2, fortigate 1 ask about the ARP of the destination IP:

in arp who-has 11.11.11.1 tell Fortigate 1

 

If the internal network of fortigate 2 sends traffic to internal networ of fortigate 1, it works.

 

I'm sure that I have not previous sessions to 11.11 network, only one route and no other routes or connected interfaces. If I do a route lookup the destination interface is the correct VPN Interface...

 

Could you help me? Why Fortigate 1 ask about ARP and it not sends traffic to the tunnel interface? I have checked routing, phase 2 selectors etc.. I can't find the problem.

 

Thanks.

1 reply

Fortimaster1
Explorer
January 30, 2026

I have changed the "wan" interface to create the tunel with another provider and now it works. Thanks, I don't know what happened but I'll  keep this new tunnel.

 

Thanks you all. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!