Question
ipsec site-to-site vpn traffic not reaching destination
Hello, I have configured a site-to-site vpn between two fortigate 300c FW and I see the tunnel come up but when I try to reach from a host (behind the firewall) from one end of the tunnel to another host at the other end of the tunnel, it does not work. I did packet captures and what I see is that if lets say if I start a ping from host1 behind fw 1 to a host2 behind fw2 then I see the icmp echo packets reaching fw2 (virtual vpn interface) but FW2 does not send it out the interface where host2 is connected. Same thing happens the other way round too. Am I missing any configuration? I would assume firewall knows the hosts that are directly connected to their interfaces and should know how to route traffic to them. But I am totally confused why this is not working. Anybody has any suggestions? Thank you.
