Skip to main content
bds38
New Member
January 9, 2018
Question

Testing a VPN with Loopback

  • January 9, 2018
  • 1 reply
  • 4237 views

Hi all,

 

This may be a really simple fix so I apologise if I sound like a dunce.

 

I have set up a site to site VPN between two customers, I have control of one of the firewalls and would like to do a ping test from the side I can control to the other side. There is a selector in phase 2 that defines 172.16.30.0/23 on the local side and 192.168.0.0/23 on the remote side. 

 

The VPN comes up fine and I am sure traffic will flow properly between both sides. I have set up a loopback IP on my side and a rule that allows the loopback adapter to traverse the VPN and access any IP on the other side. This rule also uses NAT and an IP pool with the IP address 172.16.30.193. This rule ensures that when the loopback adapter rule is applied it will use an IP address in the selector range for phase 2 and via NAT.

 

The problem I am seeing is that according to an iprope flowtrace, the loopback adapter ignores the rule and just tries to access the VPN directly. Does anyone know of a way to make the loopback adapter (or any local interfaces for that matter) use rules rather than go out ignoring them? 

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    January 9, 2018

    I'm assuming 172.16.30.0/23 is configure on the LAN side interface and all packets toward 192.168.0.0/23 including from your loopback are routed into the VPN not going to the LAN side.

    I suggest juast assigning a diffent /32 like 10.10.10.10/32 then add a new selector set 10.10.10.10/32<->192.168.0.0/23 to the phase2 without NAT.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.