Skip to main content
gohar_aziz_it
New Member
June 28, 2017
Question

IP Sec Site to Site VPN is connected but no Data Transfer

  • June 28, 2017
  • 6 replies
  • 8680 views

Hi Good Afternoon everyone,

 

I created a Site to Site IP Sec VPN between HQ and Branch and its showing its Connected and the IP are correct as well but there is no Data Transfer.

 

I created the Same Setup HQ2 to Branch and thats working.

 

HQ to Branch is pinging in CLI

Branch to HQ is not Pinging in CLI and in Log its giving this error.

 

 

Log Details from Branch

General

Date06/28/2017Time12:21:34Virtual DomainrootLog DescriptionIPsec phase 1 errorSourceLocal IPX.X.X.XUserN/AGroupN/AXAUTH UserN/AXAUTH GroupN/AActionActionnegotiateStatusnegotiate_errorReasonpeer notification

Security

Level EventAssigned IPN/ACookies334564e550384b37/d28e4abcdfa61320Local Port500Outgoing Interfaceppp1Remote IP83.110.14.120Remote Port500VPN TunnelSHJ-2-DSOMessageIPsec phase 1 error

 

 

 

    6 replies

    rwpatterson
    New Member
    June 28, 2017

    Welcome to the forums.

     

    Please check the routing table. There should be routes (if the tunnels are in interface mode). Also policies need to be made on each side in each direction. This way traffic originating from each end will be allowed through.

     

    Hope that helps.

    gohar_aziz_it
    New Member
    June 28, 2017

    I create the Static Routes and Policies Internal to VPN profile and VPN profile to Internal without NAT.

    But Still Not working.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.