Skip to main content
pxiannie
Explorer II
February 29, 2024
Question

Server IP address could not be found for IPsec VPN Remote Access

  • February 29, 2024
  • 16 replies
  • 6603 views

Hi, I'm trying to remote access to local lan using forticlient. I'm able to connect to IPsec VPN and ping 192.168.1.1 but cannot ping my server ip address and access to local server. Is there any problem for my settings? My server ip address also one of the range in Local-LAN but why I cannot ping my server? Please help.
Screenshot 2024-02-29 162511.png
Screenshot 2024-02-29 162559.png
Regards,


16 replies

abarushka
Staff
Staff
February 29, 2024

Hello,

 

You may consider to collect debug flow and traffic sniffer while pinging unreachable server:

 

Debug flow:

diagnose debug flow filter daddr <server IP address>
diagnose debug flow filter proto 1
diagnose debug flow show function-name enable
diagnose debug flow trace start 100
diagnose debug enable

 

Traffic sniffer:

diagnose sniffer packet any 'icmp and host <server IP address>' 4 0 a

pxiannie
pxiannieAuthor
Explorer II
March 7, 2024

Hi @abarushka ,

I have run the debug flow and traffic sniffer. What does it means? 

Debug flow:
Screenshot 2024-03-07 104505.png
Traffic sniffer:
Screenshot 2024-03-07 104602.png

Regards,

abarushka
Staff
Staff
March 7, 2024

Hello,

 

On firewall side everything looks good. I can see that firewall policy 7 is matched. ICMP packet is received (TONY-VPN) and sent out (interface lan). However firewall doesn't receive ICMP reply.

 

I would recommend to check whether ICMP is filtered (server OS firewall) on server side.

ebilcari
Staff
Staff
February 29, 2024

Is the server IP part of the subnet 192.168.1.x and does it use .1 as the gateway (or as a next hop in a route to reach the VPN subnet)? Check also the firewall of the server if it has any specific rule that allows or block based on source IP. If NAT is not enabled on the policy, the requests will be sourced by the IP of the VPN client.

Emirjon
pxiannie
pxiannieAuthor
Explorer II
March 7, 2024

Hi @ebilcari ,

Yes the server IP is part of the subnet 192.168.1.x and 192.168.1.1 is the default gateway used to access the GUI of a Fortinet firewall. I think the firewall of server only allow local lan subnet to access, does it mean that I need to set all the firewall policy to enabled NAT?

Regards,

ebilcari
Staff
Staff
March 7, 2024

From security perspective, it is not recommended because the source IP of the client will be hidden to the server but if that is the only way you can configure the policy to NAT the client requests with the IP of the FGT 192.168.1.1.

Emirjon
Patron
New Member
March 8, 2024

Not sure how you set it up, but you might need to add a route in the firewall explicit for the tunnel range.

Because you are using NAT and it works, it looks like that's the issue

Durga_Ashwath
Staff
Staff
March 14, 2024

Hello Team,

 

 FortiGate device is attempting to establish a connection to the FortiGuard server at IP address 173.243.143.6. This IP address does not belong to the 192.168.1.x subnet, so it's unlikely that it uses .1 as the gateway within that subnet.

Regarding firewall rules on the server, it's essential to check if there are any specific rules that might be blocking traffic from the source IP addresses of the FortiGate device or VPN clients. If there are restrictive firewall rules in place, they could potentially block the communication between the FortiGate device and the FortiGuard server.

Additionally, if NAT is not enabled on the firewall policy that allows traffic from the FortiGate device to reach external servers like the FortiGuard server, the requests will indeed be sourced by the IP of the VPN client. This means that the firewall rules on the server should allow traffic from the VPN client IPs as well, not just from the FortiGate device's IP.

In summary, it's crucial to:

  1. Check if the FortiGuard server's IP address is within the 192.168.1.x subnet and if it uses .1 as the gateway (if applicable).
  2. Review firewall rules on the server to ensure they allow traffic from both the FortiGate device's IP and the VPN client IPs.
  3. Consider enabling NAT on the firewall policy if necessary, to ensure that requests are sourced correctly.

Thank you.

pxiannie
pxiannieAuthor
Explorer II
March 14, 2024

Hi @Durga_Ashwath ,

I'm able to ping my server and server ip address in computer after added server name and server ip address in hosts file. But I still not able to access my local system in mobile, how to solve dns resolution problem in mobile? 

Regards,

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.