Skip to main content
gbrits
New Member
October 7, 2020
Question

IPSEC tunnel off connecting over PPPOE ISP connection

  • October 7, 2020
  • 1 reply
  • 7075 views

Good day .... I am not having one :)

We have a Fortigate 70C connecting to a Fortigate 300C (IPSEC VPN)

The ISP provided a 50MB Fiber internet line, and they use a PPPOE dial up "solution" to make the Internet connection "live"

 

I have installed a Fortigate 60B firewall, configured the PPPOE, added the policies, and the Line is up and running 100%

 

On the LAN side, I configured one of the public IP addresses inside the /29 range provided.

If I plug my laptop on the Public switch, configured also with one of the public IP addresses, internet works fine. So this confirm that the PPPOE setup and line and routing from ISP etc is fine.

 

But the main Fortigate 70B firewall just can't connect or make the IPSEC connection to the 300C at head office. The IPSEC config is 100%, as it was working 100%, we changed to the new ISP, worked for a week and just died.

 

ANything to look at on the 60C which does the PPPOE connection? MTU, or any IPSEC throughput rules or any help ?

    1 reply

    boneyard
    Valued Contributor
    October 10, 2020

    first off you are aware you are running old (C) / ancient (B) hardware here? which means unsupported software which doesnt get updates or security fixes. please try to get that solved as soon as possible, the nice bonus is you get Fortinet support access with better response times then a forum :) and yes im aware this specific issue is probably not hardware or software related if it did work some time ago, but still.

     

    as for the issue. you tried to restart the firewall?

     

    is the tunnel not up at all?

     

    if the tunnel is up, does no traffic work or only some, i.e. ping?

     

    you might already have found this KB article, but that is only relevant if some traffic doesn't work: https://kb.fortinet.com/k...nk.do?externalID=11731

    gbrits
    gbritsAuthor
    New Member
    October 12, 2020

    Good day 

    Yes I am aware of all the old stuff :) Not my network and not my rules, employed to look after what is given to us to work with 

     

    That out of the way :)

     

    I did all the obvious things. Fortigate 60 is on, I log onto is, pppoe connection is on, Internet is fine and fast

    The fortigate behind it, that initiates the IPSEC tunnel, makes connection but no traffic it seems 

    boneyard
    Valued Contributor
    October 16, 2020

    so you can't ping through the tunnel?

     

    and if you just browse from behind the second FortiGate, not through the tunnel? does that work?