Skip to main content
ClaudiuGheorghe90
New Member
February 19, 2024
Question

Issues: Lan to Lan Policy and VPN connection after upgrade from 7.0.13 to 7.0.14 Mature

  • February 19, 2024
  • 5 replies
  • 2817 views

Hello,

The LAN-to-LAN policies do not apply, and there is no traffic on that policy. However, with the VPN, you can connect via FortiClient, but there is no traffic, and you cannot access anything from the local network. None of the LAN IPs respond to PING, and occasionally, it disconnects from the VPN client. All of these issues have been occurring since the firmware update from version 7.0.13 to 7.0.14.

 

Somebody familiar with this issues?

5 replies

hbac
Staff
Staff
February 19, 2024

Hi @ClaudiuGheorghe90,

 

When connected to the VPN, are you able to see routes to internal network? You can run 'route print' command to check.

 

If you can see the routes, please run debug flow on the FortiGate to see what's wrong. Please refer to https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connectivity/ta-p/192560

 

Regards, 

AEK
SuperUser
SuperUser
February 19, 2024

Do you mean all lan to lan policies are not passing traffic anymore?

Do you see the legitimate traffic is being blocked in traffic log?

When you say lan IPs are not pingable do you mean FG interfaces?

AEK
Tec_Informatic
New Member
April 3, 2024
Hello, It has also happened to us. From 7.0.13 to 7.0.14 the lan to lan policies do not work and do not generate traffic either. If we download 7.0.13 everything is ok. Do we have any help?
spoojary
Staff
Staff
April 3, 2024

Run the debugs to see whether the traffic is passing from the FGT or not.

 

di deb res
diagnose debug flow filter clear
diagnose debug flow filter saddr x.x.x.x
di deb flow filter daddr x.x.x.x
diagnose debug flow show function-name enable
di deb flow show iprope en
diagnose debug console timestamp enable
diagnose debug flow trace start 999
diagnose debug enable

 

ClaudiuGheorghe90
New Member
April 4, 2024

Lan to Lan I just solved it with this: 

 

config system global
set allow-traffic-redirect disable
end

 

VPN problem: the issue was just for the clients where the vpn client had the range of IP's from the same LAN subnet, , after I changed the subnet class for vpn clients..problem solved. 

 

I hope in the next firmware update this issues will be solved. 

 

Thanks for your help! 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!