Skip to main content
Roni
New Member
November 12, 2018
Question

IPSEC VPN is up but no any traffic.

  • November 12, 2018
  • 2 replies
  • 5010 views

Hi, I`m trying to solve a problem with STS configuration.

the tunnel has created, the vpn connections is up, but there is no traffic.

when i sent ping from comp1(first FW) to comp1(second FW), unfortunately 100% Loss. Traceroute as well go to nowhere.

Thank you.

    2 replies

    brudy
    New Member
    December 7, 2018

    Hi Roni

     

    I have the same problem with on of my customers.

     

    We use IPsec, FortiClientEMS 6.0.3 and FortiOS 6.0.3. When we downgrade the client to 6.0.0 it works. We have not tried 6.0.1 or 6.0.2 yet.

     

    What versions do you have?

     

    ede_pfau
    SuperUser
    SuperUser
    December 7, 2018

    OP, I assume "STS" means site-to-site. In this case, brudy's post would not apply.

     

    You need 4 things for an IPsec VPN to work:

    - the tunnel setup itself

    - the Quick mode selectors in phase2

    - a route to the tunnel interface

    - a policy for traffic from/to the tunnel interface

     

    As long as you control both sides of the tunnel (both FGTs) you can always make it work.

    Please check that all of the above is working the way you intend it to be. For instance, in the policy table, you can set up traffic from - to and let FortiOS determine the policy it would use. Or in the routing table, you can check which route a specific traffic would use (or the absense of such).

    Then, if all is set, we can try to debug this here, with more information supplied, and you tracing live traffic on the FGT.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!