[solved] strange behaviour in ipsec site2site (was a p1 auto-negotiation issue)
Hi,
I have the following setup here:
Side A:
FGT 100E with 6.0.9
lan subnet is xx.xx.xx.0/24
Side B:
FGT 80C with 5.6.12 (latest available for 80C)
lan subnet is yy.yy.yy.0/24
IPSec Site2Site between A and B is set up.
The Tunnel is up (green in monitor) and monitor does show there is traffic in both directions on this one.
now when I ping xx.xx.xx.10 from client yy.yy.yy.50 on Side B I get no response.
Flow Trace on Side B shows that the traffic goes out to side A over the IPsec as it should.
Flow Trace on Side A shows that the traffic coming from my client does reach side A and is routed on correctly
Flow Trace on Side A also shows me that there is traffic from xx.xx.xx.10 to my client and that it is routed over the Ipsec correctly.
However: Flow Trace on Side B with Filter saddr xx.xx.xx.10 and daddr yy.yy.yy.50 shows just nothing.
So looks to me as if the traffic coming back to my client on side B gets lost somewhere on the ipsec?
Did anyone here have this? Any clues?
Thnx in advance!
Sebastian
