Skip to main content
hungran91
New Member
March 28, 2016
Question

IP SEC INTERFACE UP. PING AT FORTIGATE DOES'N WORK!

  • March 28, 2016
  • 1 reply
  • 3790 views

I have 2 FG 60D (local: 192.168.20.254) n 200A (192.168.5.254) using VPN interface mode.

IPsec mornitor is up. I can use RDP, and Local can ping betwen together. I can ping from FG 200A to 192.168.20.254 ok. But i cannot ping from FG 60 to 192.168.5.254 or any device remote site.

PLS help!

 

    1 reply

    ede_pfau
    SuperUser
    SuperUser
    March 28, 2016

    Do you have policies for both directions?

    hungran91
    hungran91Author
    New Member
    March 28, 2016
    Yes. On FG 60D i have to use exe ping-options source 192.168.20.254 first then i can ping to 192.168.5.254.
    hungran91
    hungran91Author
    New Member
    March 29, 2016
    hungran91 wrote:
    Yes. On FG 60D i have to use exe ping-options source 192.168.20.254 first then i can ping to 192.168.5.254.
    But when i logout/login again, it doesnt work. The traffic have only one subnet (192.168.5.0/24) can through over VPN. But on FG 200A i have some static routes. And on FG 60D i was added static routes with device VPN P1 from FG 200A (distance lower than default route).