Trying to connect Fortigate to Radius Server (FortiAuth) over IPSec
I have an established IPSec tunnel with 1 host on each side. Windows AD is local (192.168.11.254) and FortiAuth is remote (1.0.0.231). I have good traffic and the Auth is able to import LDAP users and shows a valid connection.
I am trying to add the Forti 80CM as a Radius client and the test fails. I ran ping and traceroute from the CLI on the firewall with no success. I ran sniffer and see there is nothing with the firewall IP in the output.
Policy is wide open, source and destination are "all" and service is "all". No NAT, no security policies.
Do I need to add the firewall to the VPN policy?
I have a feeling I'm missing something easy.
diagnose sniffer packet 'VPN AE[KWS Static' none 4 interfaces=[VPN AWS Static] filters=[none] 4.255542 VPN AWS Static -- 10.0.0.231.54034 -> 192.168.11.254.445: psh 3524084358 ack 1433518151 4.256254 VPN AWS Static -- 192.168.11.254.445 -> 10.0.0.231.54034: psh 1433518151 ack 3524084566 4.289899 VPN AWS Static -- 10.0.0.231.54034 -> 192.168.11.254.445: ack 1433518315 4.290021 VPN AWS Static -- 10.0.0.231.54034 -> 192.168.11.254.445: psh 3524084566 ack 1433518315
