Skip to main content
dadya06
New Member
January 22, 2025
Question

Strange domain controller one way sync problem fortigate s2s vpn

  • January 22, 2025
  • 1 reply
  • 358 views

Hi,

We have this system admin team who is complaining that whenever our VPN tunnel is shifted from one internet provider to another the active directory sync will work one way for example from domain controller A to B but not from B to A. Any object created or deleted on B will not reflect on A but any changes on A will reflect on B. Very strange thing as no change except the underlay ISP link.

All traffic flows inside VPN tunnel in both working and non working cases.

1 reply

AEK
SuperUser
SuperUser
January 23, 2025

Hi Dadya

Try enable logs on the related rules and on the implicit deny rule as well, then check if any related traffic is blocked.

Also check if your phase2 selector include the required subnets from both sides.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!