Skip to main content
Ratschko
New Member
March 2, 2016
Question

IPSEC Rule will not be triggered

  • March 2, 2016
  • 11 replies
  • 9299 views

Hi!

 

I have a strange issue. On our 800C (V5.2.6) Cluster, i create a new IPSEC Policy Rule..like many others. But this rule seems

not to be triggered.

Source is 10.98.42.xxx and Dest is 192.168.199.100

 

Flow Diag:

id=20085 trace_id=27 func=print_pkt_detail line=4471 msg="vd-root received a packet(proto=1, 10.98.42.140:32773->192.168.199.100:8) from port3. code=8, type=0, id=32773, seq=0." id=20085 trace_id=27 func=init_ip_session_common line=4622 msg="allocate a new session-03b89454" id=20085 trace_id=27 func=vf_ip4_route_input line=1596 msg="find a route: flags=00000000 gw-217.89.79.3 via wan1" id=20085 trace_id=27 func=fw_forward_handler line=675 msg="Allowed by Policy-4: SNAT" id=20085 trace_id=27 func=ids_receive line=246 msg="send to ips" id=20085 trace_id=27 func=__ip_session_run_tuple line=2599 msg="SNAT 10.98.42.140->217.89.79.6:62464"

 

Policy (4) is our common Rule for Outside Access with NAT, but its nearly at the Ende of the policy (See Screenshot).

 

I have no idea where to start debugging. Has someone an Idea?

 

 

 

    11 replies

    emnoc
    New Member
    March 2, 2016

    I would start via the route, remember route for SNAT traffic takes 1st this how/why the traffic goes out of the wan1 fo dst subnet 192.168.199.100

     

     

    Ratschko
    RatschkoAuthor
    New Member
    March 2, 2016

    Sorry..many questions marks over my head :)

     

    What do you mean where i could search?

    emnoc
    New Member
    March 2, 2016

    cli show router static would be a start, or from the webgui system >  routes > static-route  & after the vpn is up look in the route monitor for that destination

     

    Above is all assuming this is a route-based vpn and that you have a "named phase1-interface"

     

    Read the fortigate cookbook,but they have done a great job crafting howto for ipsec  route-based vpns.

     

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!