Skip to main content
Dizzy_Read
New Member
August 14, 2017
Question

Site to Site IPSEC problems

  • August 14, 2017
  • 12 replies
  • 15734 views

 

Hi!

 

We have some problem with routing? via IPSec site to site

 

1. 2 ISP on both side, 4 ipsec tunnels from Branch site (60c) to mail office (1000c).

2. Phase 2 on all tunnels 0.0.0.0/0.0.0.0 as networks, static routes with different distance (1-2-3-4) for IPSEC failover.  

3. "LAN" 192.168.7.0/24 on 60С and "LAN" 192.168.0.0/24 on 1000C

4. FW on 60c and 1000c 5.2.11 latest

5. All work fine, traffic flow from any LANs to any LANs via IPSec BUT ...

 

If trace route from LAN 192.168.0.0 host to host in 192.168.7.0 i see, WAN1 IP of 60C in trace route ....

 

1    <1 ms    <1 ms    <1 ms  192.168.0.251 (1000C LAN IP) 2     3 ms     3 ms     2 ms  xx.xx.xx.xx (60C WAN1 IP) 3     3 ms     2 ms     2 ms  host5 [192.168.7.1] (host in 192.168.7.0 network)

 

Why traffic flow like this ??? We have few others devices connected same way - no tracert problems!!!

 

We try check any settings - all the same, only difference - connected ports. We think - traffic flow as ifindex of port on FGT ????

 

How we can resolve issue?

 

We have troubles with applications like TMG 2010 - client source IP (WAN IP 60c) unreachable in logs ...

 

Tnx for any help! 

 

    12 replies

    bommi
    New Member
    August 15, 2017

    This is not an issue.

    Your tunnel interfaces are unnumbered, your fortigate just takes some ip-adress to display in the output.

     

    This behavior is documented here:

    http://kb.fortinet.com/kb/documentLink.do?externalID=FD36799

     

    Regards

    bommi

    emnoc
    New Member
    August 15, 2017

    fwiw , you can  add  address to the tunnel interfaces.

    Dizzy_Read
    New Member
    August 22, 2017

    Hi! Can anyone help with issues ?

    oheigl
    New Member
    August 22, 2017

    What do you mean by check this source IPs? What's the IP of the TMG and on which location is it? We need some more information to help you on this case.

    Dizzy_Read
    New Member
    August 24, 2017

    Antonio, tnx again for help ! )))

     

    MTU test to problem side (192.168.1.0/24 network)

     

    mturoute.exe -t 192.168.1.1 mturoute to 192.168.1.1, 30 hops max, variable sized packets * ICMP Fragmentation is not permitted. * * Speed optimization is enabled. * * Maximum payload is 10000 bytes. *  1  +-  host: 192.168.0.251  max: 1500 bytes  2  No response from traceroute for this TTL.  Tried 3 times  - WHY ?  3  -+++++-+...-++++  host: 192.168.1.1  max: 1444 bytes

     

    D:\mturoute.exe 192.168.1.1 * ICMP Fragmentation is not permitted. * * Speed optimization is enabled. * * Maximum payload is 10000 bytes. * - ICMP payload of 1472 bytes is too big. + ICMP payload of 92 bytes succeeded. + ICMP payload of 782 bytes succeeded. + ICMP payload of 1127 bytes succeeded. + ICMP payload of 1299 bytes succeeded. + ICMP payload of 1385 bytes succeeded. - ICMP payload of 1428 bytes is too big. + ICMP payload of 1406 bytes succeeded. ...- ICMP payload of 1417 bytes failed. (IP_REQ_TIMED_OUT) - ??? + ICMP payload of 1411 bytes succeeded. + ICMP payload of 1414 bytes succeeded. + ICMP payload of 1415 bytes succeeded. + ICMP payload of 1416 bytes succeeded. Path MTU: 1444 bytes.

     

    MTU test to NO problem side (192.168.5.0/24 network)

     

    D:\mturoute.exe -t 192.168.5.1 mturoute to 192.168.5.1, 30 hops max, variable sized packets * ICMP Fragmentation is not permitted. * * Speed optimization is enabled. * * Maximum payload is 10000 bytes. *  1  +-  host: 192.168.0.251  max: 1500 bytes  2  -+++++-++--+  host: 192.168.5.254  max: 1446 bytes  3  -+++++++++++-  host: 192.168.5.1  max: 1444 bytes

     

    mturoute.exe 192.168.5.1 * ICMP Fragmentation is not permitted. * * Speed optimization is enabled. * * Maximum payload is 10000 bytes. * - ICMP payload of 1472 bytes is too big. + ICMP payload of 92 bytes succeeded. + ICMP payload of 782 bytes succeeded. + ICMP payload of 1127 bytes succeeded. + ICMP payload of 1299 bytes succeeded. + ICMP payload of 1385 bytes succeeded. - ICMP payload of 1428 bytes is too big. + ICMP payload of 1406 bytes succeeded. - ICMP payload of 1417 bytes is too big. + ICMP payload of 1411 bytes succeeded. + ICMP payload of 1414 bytes succeeded. + ICMP payload of 1415 bytes succeeded. + ICMP payload of 1416 bytes succeeded. Path MTU: 1444 bytes.

     

    Effective MTU 1444 ?  I need to lower it on FGT (as i know, i can't do it on ipsec interface) or on WinSrv ? 

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!