Skip to main content
Anthony2
New Member
July 22, 2026
Question

I havinf issues with both Hub loops when ping from Spoke for FortiOS 7.6.6

  • July 22, 2026
  • 9 replies
  • 48 views

Hello Team 

I have configured ADVPN 2.0 between two 120G, BGP is up, i can ping both tunnels, but the issues are that i can ping the Hub loopback from the Spoke but unable the Hub loopback from the Spoke 

 

 

9 replies

funkylicious
SuperUser
SuperUser
July 22, 2026

when you ping the Hub-Lo from the spoke, which source address are you using ? the tunnel IP if any is set or a Loopback on the Spoke?

can you confirm via sniffer and/or diag debug that traffic originating from Spoke towards the Hub, on the Hub is visible/reaches the FGT ? 

I assume that routes are correctly advertised by each FGT

also, are firewall rules in place that grants/permits this traffic ?

"jack of all trades, master of none"
Anthony2
Anthony2Author
New Member
July 22, 2026

From the Hub the ping traffic goes through the Tunnel, yes the BGP is up and i am advertising the correct subnet on both sides, this when i did to setup the SDwan but the SDwan now disable, let me share some diag with you 

Anthony2
Anthony2Author
New Member
July 22, 2026

FG120G_Hub # diagnose sniffer packet any 'icmp and host 10.6.0.254' 4\702\640\702\640

interfaces=[any]

filters=[icmp and host 10.6.0.254]

18.713134 ISPbWIN2 in 169.254.40.11 -> 10.6.0.254: icmp: echo request

19.713134 ISPbWIN2 in 169.254.40.11 -> 10.6.0.254: icmp: echo request

20.713189 ISPbWIN2 in 169.254.40.11 -> 10.6.0.254: icmp: echo request

21.713248 ISPbWIN2 in 169.254.40.11 -> 10.6.0.254: icmp: echo request

22.713250 ISPbWIN2 in 169.254.40.11 -> 10.6.0.254: icmp: echo request

54.141584 ISPbWIN2 in 169.254.40.11 -> 10.6.0.254: icmp: echo request

55.141638 ISPbWIN2 in 169.254.40.11 -> 10.6.0.254: icmp: echo request

56.141651 ISPbWIN2 in 169.254.40.11 -> 10.6.0.254: icmp: echo request

57.141703 ISPbWIN2 in 169.254.40.11 -> 10.6.0.254: icmp: echo request

58.141760 ISPbWIN2 in 169.254.40.11 -> 10.6.0.254: icmp: echo request

Anthony2
Anthony2Author
New Member
July 22, 2026

FG120G_Hub # diagnose debug flow filter addr 10.6.0.254

FG120G_Hub # diagnose debug flow filter proto 1

FG120G_Hub # diagnose debug flow show console enable

G120G_Hub # diagnose debug enabl

FG120G_Hub # diagnose debug flow trace start 10

!

FG120G_Hub # id=65308 trace_id=1 func=print_pkt_detail line=6336 msg="vd-root:0 received a packet(proto=1, 169.254.40.11:10->10.6.0.254:2048) tun_id=169.254.40.11 from ISPbWIN2. type=8, code=0, id=10, seq=0."

id=65308 trace_id=1 func=ipsec_spoofed4 line=221 msg="src ip 169.254.40.11 match selector 0 range 0.0.0.0-255.255.255.255"

id=65308 trace_id=1 func=init_ip_session_common line=6550 msg="allocate a new session-000019d5"

id=65308 trace_id=1 func=__vf_ip_route_input_rcu line=2116 msg="find a route: flag=80000000 gw-0.0.0.0 via root"

id=65308 trace_id=1 func=__iprope_tree_check line=524 msg="gnum-100004, use int hash, slot=111, len=2"

id=65308 trace_id=1 func=fw_local_in_handler line=630 msg="iprope_in_check() check failed on policy 0, drop"

id=65308 trace_id=2 func=print_pkt_detail line=6336 msg="vd-root:0 received a packet(proto=1, 169.254.40.11:10->10.6.0.254:2048) tun_id=169.254.40.11 from ISPbWIN2. type=8, code=0, id=10, seq=1."

id=65308 trace_id=2 func=ipsec_spoofed4 line=221 msg="src ip 169.254.40.11 match selector 0 range 0.0.0.0-255.255.255.255"

id=65308 trace_id=2 func=init_ip_session_common line=6550 msg="allocate a new session-000019da"

id=65308 trace_id=2 func=__vf_ip_route_input_rcu line=2116 msg="find a route: flag=80000000 gw-0.0.0.0 via root"

id=65308 trace_id=2 func=__iprope_tree_check line=524 msg="gnum-100004, use int hash, slot=111, len=2"

id=65308 trace_id=2 func=fw_local_in_handler line=630 msg="iprope_in_check() check failed on policy 0, drop"

id=65308 trace_id=3 func=print_pkt_detail line=6336 msg="vd-root:0 received a packet(proto=1, 169.254.40.11:10->10.6.0.254:2048) tun_id=169.254.40.11 from ISPbWIN2. type=8, code=0, id=10, seq=2."

id=65308 trace_id=3 func=ipsec_spoofed4 line=221 msg="src ip 169.254.40.11 match selector 0 range 0.0.0.0-255.255.255.255"

id=65308 trace_id=3 func=init_ip_session_common line=6550 msg="allocate a new session-000019de"

id=65308 trace_id=3 func=__vf_ip_route_input_rcu line=2116 msg="find a route: flag=80000000 gw-0.0.0.0 via root"

id=65308 trace_id=3 func=__iprope_tree_check line=524 msg="gnum-100004, use int hash, slot=111, len=2"

id=65308 trace_id=3 func=fw_local_in_handler line=630 msg="iprope_in_check() check failed on policy 0, drop"

id=65308 trace_id=4 func=print_pkt_detail line=6336 msg="vd-root:0 received a packet(proto=1, 169.254.40.11:10->10.6.0.254:2048) tun_id=169.254.40.11 from ISPbWIN2. type=8, code=0, id=10, seq=3."

id=65308 trace_id=4 func=ipsec_spoofed4 line=221 msg="src ip 169.254.40.11 match selector 0 range 0.0.0.0-255.255.255.255"

id=65308 trace_id=4 func=init_ip_session_common line=6550 msg="allocate a new session-000019e2"

id=65308 trace_id=4 func=__vf_ip_route_input_rcu line=2116 msg="find a route: flag=80000000 gw-0.0.0.0 via root"

id=65308 trace_id=4 func=__iprope_tree_check line=524 msg="gnum-100004, use int hash, slot=111, len=2"

id=65308 trace_id=4 func=fw_local_in_handler line=630 msg="iprope_in_check() check failed on policy 0, drop"

id=65308 trace_id=5 func=print_pkt_detail line=6336 msg="vd-root:0 received a packet(proto=1, 169.254.40.11:10->10.6.0.254:2048) tun_id=169.254.40.11 from ISPbWIN2. type=8, code=0, id=10, seq=4."

id=65308 trace_id=5 func=ipsec_spoofed4 line=221 msg="src ip 169.254.40.11 match selector 0 range 0.0.0.0-255.255.255.255"

id=65308 trace_id=5 func=init_ip_session_common line=6550 msg="allocate a new session-000019e7"

id=65308 trace_id=5 func=__vf_ip_route_input_rcu line=2116 msg="find a route: flag=80000000 gw-0.0.0.0 via root"

id=65308 trace_id=5 func=__iprope_tree_check line=524 msg="gnum-100004, use int hash, slot=111, len=2"

id=65308 trace_id=5 func=fw_local_in_handler line=630 msg="iprope_in_check() check failed on policy 0, drop"

and excate ping from the Spoke to the Hub 

funkylicious
SuperUser
SuperUser
July 22, 2026

id=65308 trace_id=2 func=fw_local_in_handler line=630 msg="iprope_in_check() check failed on policy 0, drop"

which means either no firewall rule is in place from ISPbWIN2 towards the destination interface to allow the traffic, or PING is not enabled under that interface on the FGT

"jack of all trades, master of none"
Anthony2
Anthony2Author
New Member
July 22, 2026

Thanks

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!