Strange behavior for a dialup VPN unable to ping from one side but other OK (in part)..
- April 14, 2020
- 2 replies
- 4264 views
Hi forum.
I have not too much experience with Fortigate VPN but I have searched the forum and did not found the answer to my question since my setup is very unlikely.
I needed to connect two offices via two identical Fortigate 30E and due to internal policies of the company, while HQ_1 uses the Fortigate as Router and firewall and has its WAN directly connected to the Public IP address, the HQ_2 uses a proprietary router and their Fortigate 30E WAN is connected to one LAN port of the router in the internal subnet.
Have forwarded inside the proprietary router 4500 and 500 pointed.
I have drawn the configuration in order to explain better my case.
In order to instantiate a VPN between the two offices, I have followed the good guide and different thread I have found in this forum. And the VPN is up.
However following problems occur:
inside the CLI of Fortigate HQ_2 (the one behind the NAT) I can ping and see:
Fortigate of HQ_1
all devices in subnet of Office 1.
inside the CMD line of any device inside subnet of HQ_2 (the one behind the NAT) I cannot ping nor see devices in subnet of Office 1.
And
inside the CLI of Fortigate HQ_1 I cannot ping FortigateRouter2, the local IP address of proprietary router nor any devices in subnet of Office 2.
but:
inside the CMD of any device inside subnet of HQ_1 (the one behind the NAT) I ping successfully FortigateRouter2, but cannot all devices in subnet of Office 2.
So the question is:
Does such a configuration present some major error?
Can anone help to explain this?
Best regards and thank You all
Steve