Skip to main content
AUT_Maverick
Visitor III
July 26, 2023
Question

IPSec Routing

  • July 26, 2023
  • 3 replies
  • 1329 views

We have established a VPN connection with a FortiGate firewall in Stockerau.
Steyr -> Stockerau works.
Stockerau -> Steyr unfortunately not, it is not routed into the VPN tunnel although there is a static route with 10.30.0.0/16.

3 replies

kmohan
Staff
Staff
July 26, 2023

Hi,

Check the inbound and outbound traffic on the policy
then check static route the Steyr is traffic send via same GW or not

 

kmohan
Staff
Staff
July 26, 2023

Take debug flow 

 

 

princes
Staff
Staff
July 26, 2023

Hi,

You need to make sure the route which you have created for this particular destination should be active in the routing table.

# get router info routing-table details 10.30.0.0

(Make sure the route should be shown with * sign)

Also make sure there is no policy route created for the same with any other interface.

Also make sure you have outbound policy allowing traffic from your LAN towards the tunnel interface.

If you still see the traffic for this subnet is taking default route instead of tunnel interface route, verify the flow with debug flow.


# diagnose debug flow filter sa <source-IP_lan-PC>
# diagnose debug flow filter da <10.30.0.x>
# diagnose debug flow show function-name enable
# diagnose debug flow trace start 100
# diagnose debug enable

You can also refer the below article for debugs:

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPN-is-up-but-network-is-not-reachable/ta-p/192887

Regards,

prince

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!