Skip to main content
TJNIHAL
New Member
March 25, 2019
Solved

Site-to-site IPsec VPN with two FortiGates

  • March 25, 2019
  • 11 replies
  • 14349 views

Hi,

I have 2 Fortinet device 60E and 60D. I have been trying to create a VPN tunnel between the device.   I followed this cookbook article https://cookbook.fortinet.com/site-site-ipsec-vpn-two-fortigates-56/ and both my devices are behind the NAT So, I had to change the NAT setting beside I followed every single step mentioned in this article.  In the end tunnel is NOT UP so, I tried to converted the tunnel to custom and disabled NAT-T, then tunnel is UP but traffic is not passing. Not sure where to look for issue. Any guidance highly appreciate. Both devices have v5.6.2 build1486 (GA) firmware.   Thanks.

Best answer by JackieTF

Hi TJ,

 

I can think of few things that you might want to check: 1. Traffic not passing from which site to which site? 2. Is there subnet conflict on both end? (mean both site have same local network) 3. check routing: get router info routing-table details x.x.x.x , replace the x.x.x.x with destination address 4. check policy, make sure policy is created for both direction with NAT disabled. 5. Finally, check debug flow and packet sniffer.

 

Regards, Jackie

11 replies

JackieTF
JackieTFAnswer
New Member
March 25, 2019

Hi TJ,

 

I can think of few things that you might want to check: 1. Traffic not passing from which site to which site? 2. Is there subnet conflict on both end? (mean both site have same local network) 3. check routing: get router info routing-table details x.x.x.x , replace the x.x.x.x with destination address 4. check policy, make sure policy is created for both direction with NAT disabled. 5. Finally, check debug flow and packet sniffer.

 

Regards, Jackie

TJNIHAL
TJNIHALAuthor
New Member
March 26, 2019

Hi Jackie, Thanks for your reply,

 

1. Traffic not passing from which site to which site?

             Traffic not passing from both site 

2. Is there subnet conflict on both end? (mean both site have same local network)

             No, both site has unique subnet. (both site router is behind NAT connected to the Modem with the same subnet 192.168.0.1/24) But both router has different LAN subnet starting 10.x.x.x/24.    3. check routing:

             double checked the routing its perfect.

              get router info routing-table details x.x.x.x , replace the x.x.x.x with destination address

 

FGT60E # get router info routing-table details 10.1.3.5
Routing entry for 10.1.3.0/24
 Known via "static", distance 10, metric 0, best
 * directly connected, Test_VPN
 
Routing entry for 10.1.3.0/24
 Known via "static", distance 254, metric 0
 directly connected, Null

FGT60D # diag vpn ike gateway flush
 
FGT60D4Q15011598 # get router info routing-table details 10.1.1.5
Routing entry for 10.1.1.0/24
 Known via "static", distance 10, metric 0, best
 * directly connected, Test_VPN
 
Routing entry for 10.1.1.0/24
 Known via "static", distance 254, metric 0
 directly connected, Null

4. check policy, make sure policy is created for both direction with NAT disabled.

       in/out Polices created on both device with NAT disabled 5. Finally, check debug flow and packet sniffer.

      Not sure which cli command you are referring. 

 

 

sw2090
SuperUser
SuperUser
March 27, 2019

hm I am not sure if a flow debug will help here...it will only show you where your traffic goes and if it is allowed or not.

You might have more to look at the ipsec debug log. But beware that IPSEC debugging is a pain in the a*** :(

 

Basically: 

 

1st pitfall: vpn tunnels on fgt do not come up if there is no policy for traffic on them.

 

if that is not the case mostly some settings of your tunnel do not match both sides. Mostly that is proposals, psk or peer ids (if used). You might see this in the ipsec debug log.

 

To see this use:

 

  diag debug ena

  diag debug application ike -1

 

then watch and see...

 

 

sangomab
New Member
March 27, 2019

Hi there, try this,     [size="3"]

diagnose debug disable
diagnose debug reset
diagnose vpn ike gateway clear
diagnose vpn ike log filter name YOUR_VPN_NAME
diagnose debug application ike -1
diagnose debug enable
 [/size]   and send back the logs   di de di to disable diagnose

sw2090
SuperUser
SuperUser
March 28, 2019

unfortunately most of the log fiters are broken in fortios and don't work at all. Fortinet know this but don't fix it at least in 5.4.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.