Skip to main content
Umirzak
Visitor III
June 18, 2024
Solved

unable to ping and open local web server from branch office.

  • June 18, 2024
  • 16 replies
  • 8424 views

I have two fortigate 60F which connected via ipsec (HQ office and branch office)

I need to allow users from branch office to connect to HQ's web server. 

currently i can ping from HQ to branch office users, but not able from branch to HQ's office.

I am new to fortigate configuration, guys can u help me what i need to configure?

 

Best answer by Umirzak

resolved, on branch side the IPSec vpn settings was wrong (Wrong interface)

16 replies

Sherman_P
Staff
Staff
June 18, 2024

Hi @Umirzak ,

 

Is PING allowed on HQ office? Sometime it has something to do with the Windows Firewall so it is worth checking. You may refer to the following article:

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Unable-to-Ping-Destination-Host-Connected/ta-p/278507

Umirzak
UmirzakAuthor
Visitor III
June 18, 2024

just tried to debug from fortigate on branch office

 

tengizfg # dia deb flow filter addr 192.168.50.99 (this is HQ's Fortifate)

tengizfg # dia deb flow filter proto 1

tengizfg # dia deb flow trace start 100

tengizfg # dia deb en

tengizfg #
tengizfg # id=65308 trace_id=92 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=1, 192.168.1.150:1->192.168.50.99:2048) tun_id=0.0.0.0 from Teng
izlan. type=8, code=0, id=1, seq=96."
id=65308 trace_id=92 func=init_ip_session_common line=6009 msg="allocate a new session-00248759, tun_id=0.0.0.0"
id=65308 trace_id=92 func=vf_ip_route_input_common line=2611 msg="find a route: flag=04000000 gw-89.218.165.138 via 2HQ"
id=65308 trace_id=92 func=__iprope_tree_check line=528 msg="gnum-100004, use int hash, slot=32, len=1"
id=65308 trace_id=92 func=fw_forward_handler line=827 msg="Denied by forward policy check (policy 0)"
id=65308 trace_id=93 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=1, 192.168.1.150:1->192.168.50.99:2048) tun_id=0.0.0.0 from Tengizlan. type
=8, code=0, id=1, seq=97."
id=65308 trace_id=93 func=init_ip_session_common line=6009 msg="allocate a new session-002487fa, tun_id=0.0.0.0"
id=65308 trace_id=93 func=vf_ip_route_input_common line=2611 msg="find a route: flag=04000000 gw-89.218.165.138 via 2HQ"
id=65308 trace_id=93 func=__iprope_tree_check line=528 msg="gnum-100004, use int hash, slot=32, len=1"
id=65308 trace_id=93 func=fw_forward_handler line=827 msg="Denied by forward policy check (policy 0)"
id=65308 trace_id=94 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=1, 192.168.1.150:1->192.168.50.99:2048) tun_id=0.0.0.0 from Tengizlan. type
=8, code=0, id=1, seq=98."
id=65308 trace_id=94 func=init_ip_session_common line=6009 msg="allocate a new session-0024887c, tun_id=0.0.0.0"
id=65308 trace_id=94 func=vf_ip_route_input_common line=2611 msg="find a route: flag=04000000 gw-89.218.165.138 via 2HQ"
id=65308 trace_id=94 func=__iprope_tree_check line=528 msg="gnum-100004, use int hash, slot=32, len=1"
id=65308 trace_id=94 func=fw_forward_handler line=827 msg="Denied by forward policy check (policy 0)"
id=65308 trace_id=95 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=1, 192.168.1.150:1->192.168.50.99:2048) tun_id=0.0.0.0 from Tengizlan. type
=8, code=0, id=1, seq=99."
id=65308 trace_id=95 func=init_ip_session_common line=6009 msg="allocate a new session-002488cd, tun_id=0.0.0.0"
id=65308 trace_id=95 func=vf_ip_route_input_common line=2611 msg="find a route: flag=04000000 gw-89.218.165.138 via 2HQ"
id=65308 trace_id=95 func=__iprope_tree_check line=528 msg="gnum-100004, use int hash, slot=32, len=1"
id=65308 trace_id=95 func=fw_forward_handler line=827 msg="Denied by forward policy check (policy 0)"
id=65308 trace_id=96 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=1, 192.168.1.150:1->192.168.50.99:2048) tun_id=0.0.0.0 from Tengizlan. type
=8, code=0, id=1, seq=100."
id=65308 trace_id=96 func=init_ip_session_common line=6009 msg="allocate a new session-00248927, tun_id=0.0.0.0"
id=65308 trace_id=96 func=vf_ip_route_input_common line=2611 msg="find a route: flag=04000000 gw-89.218.165.138 via 2HQ"
id=65308 trace_id=96 func=__iprope_tree_check line=528 msg="gnum-100004, use int hash, slot=32, len=1"
id=65308 trace_id=96 func=fw_forward_handler line=827 msg="Denied by forward policy check (policy 0)"
id=65308 trace_id=97 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=1, 192.168.1.150:1->192.168.50.99:2048) tun_id=0.0.0.0 from Tengizlan. type
=8, code=0, id=1, seq=101."
id=65308 trace_id=97 func=init_ip_session_common line=6009 msg="allocate a new session-002489a1, tun_id=0.0.0.0"
id=65308 trace_id=97 func=vf_ip_route_input_common line=2611 msg="find a route: flag=04000000 gw-89.218.165.138 via 2HQ"
id=65308 trace_id=97 func=__iprope_tree_check line=528 msg="gnum-100004, use int hash, slot=32, len=1"
id=65308 trace_id=97 func=fw_forward_handler line=827 msg="Denied by forward policy check (policy 0)"
id=65308 trace_id=98 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=1, 192.168.1.150:1->192.168.50.99:2048) tun_id=0.0.0.0 from Tengizlan. type
=8, code=0, id=1, seq=102."
id=65308 trace_id=98 func=init_ip_session_common line=6009 msg="allocate a new session-00248a1a, tun_id=0.0.0.0"
id=65308 trace_id=98 func=vf_ip_route_input_common line=2611 msg="find a route: flag=04000000 gw-89.218.165.138 via 2HQ"
id=65308 trace_id=98 func=__iprope_tree_check line=528 msg="gnum-100004, use int hash, slot=32, len=1"
id=65308 trace_id=98 func=fw_forward_handler line=827 msg="Denied by forward policy check (policy 0)"

abarushka
Staff
Staff
June 18, 2024

Hello,

 

I would recommend to check whether IPsec phase2 subnets are configured correctly and whether firewall policies are configured on both sides.

 

You may consider to sniff the traffic and collect debug flow in order to isolate the issue while the issue is reproduced:

 

Sniffer:

 

diagnose sniffer packet any 'host <destination IP address>' 4 0 a

 

Debug flow:

 

diagnose debug flow filter daddr <destination IP address>
diagnose debug flow show function-name enable
diagnose debug flow trace start 100
diagnose debug enable

Umirzak
UmirzakAuthor
Visitor III
June 18, 2024

this is extract from my HQs fortigate, tried to perform same commands on brancha fortigate it gives me nothing

 

uzkfghq # diagnose sniffer packet any host 192.168.1.150 4 0 a
interfaces=[any]
filters=[host]
pcap_snapshot: snaplen raised from 0 to 262144
pcap_compile: can't parse filter expression: syntax error

uzkfghq # diagnose debug flow filter daddr 192.168.1.150

uzkfghq # diagnose debug flow show function-name enable
show function name

uzkfghq # diagnose debug flow trace start 100

uzkfghq # diagnose debug enable

uzkfghq # id=65308 trace_id=12 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.50.197:49572->192.168.1.150:3389) tun_id=0.0.0.0 from
internal. flag [.], seq 2231500958, ack 1035991134, win 511"
id=65308 trace_id=12 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0877472b, original direction"
id=65308 trace_id=12 func=ipv4_fast_cb line=53 msg="enter fast path"
id=65308 trace_id=12 func=ipsecdev_hard_start_xmit line=669 msg="enter IPSec interface 2Tengiz-HQ, tun_id=0.0.0.0"
id=65308 trace_id=12 func=_do_ipsecdev_hard_start_xmit line=229 msg="output to IPSec tunnel 2Tengiz-HQ vrf 0"
id=65308 trace_id=12 func=esp_output4 line=896 msg="IPsec encrypt/auth"
id=65308 trace_id=12 func=ipsec_output_finish line=629 msg="send to 89.218.165.137 via intf-wan1"
id=65308 trace_id=13 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=17, 192.168.50.197:63315->192.168.1.150:3389) tun_id=0.0.0.0 from internal.
"
id=65308 trace_id=13 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-08774731, original direction"
id=65308 trace_id=13 func=ipv4_fast_cb line=53 msg="enter fast path"
id=65308 trace_id=13 func=ipsecdev_hard_start_xmit line=669 msg="enter IPSec interface 2Tengiz-HQ, tun_id=0.0.0.0"
id=65308 trace_id=13 func=_do_ipsecdev_hard_start_xmit line=229 msg="output to IPSec tunnel 2Tengiz-HQ vrf 0"
id=65308 trace_id=13 func=esp_output4 line=896 msg="IPsec encrypt/auth"
id=65308 trace_id=13 func=ipsec_output_finish line=629 msg="send to 89.218.165.137 via intf-wan1"
id=65308 trace_id=14 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.50.197:49572->192.168.1.150:3389) tun_id=0.0.0.0 from internal.
flag [.], seq 2231500958, ack 1035991235, win 511"
id=65308 trace_id=14 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0877472b, original direction"
id=65308 trace_id=14 func=ipv4_fast_cb line=53 msg="enter fast path"
id=65308 trace_id=14 func=ipsecdev_hard_start_xmit line=669 msg="enter IPSec interface 2Tengiz-HQ, tun_id=0.0.0.0"
id=65308 trace_id=14 func=_do_ipsecdev_hard_start_xmit line=229 msg="output to IPSec tunnel 2Tengiz-HQ vrf 0"
id=65308 trace_id=14 func=esp_output4 line=896 msg="IPsec encrypt/auth"
id=65308 trace_id=14 func=ipsec_output_finish line=629 msg="send to 89.218.165.137 via intf-wan1"
id=65308 trace_id=15 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.50.197:49572->192.168.1.150:3389) tun_id=0.0.0.0 from internal.
flag [.], seq 2231500958, ack 1035991336, win 510"

 

Umirzak
UmirzakAuthor
Visitor III
June 18, 2024

finally i need to open port 80, 443 from remote fortigate. 

abarushka
Staff
Staff
June 18, 2024

Hello,

 

There is a typo in the sniffer. Correct syntax: "diagnose sniffer packet any 'host 192.168.1.150' 4 0 a"

 

As far as I understand the issue is resolved. If it is correct, please tag the thread as resolved.

Umirzak
UmirzakAuthor
Visitor III
June 19, 2024

ok see below 

uzkfghq # diagnose sniffer packet any 'host 192.168.1.150' 4 0 a
interfaces=[any]
filters=[host 192.168.1.150]
2024-06-19 07:50:40.786918 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
2024-06-19 07:50:42.802375 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
2024-06-19 07:50:44.802757 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
2024-06-19 07:50:46.806683 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
2024-06-19 07:50:48.827926 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
2024-06-19 07:50:50.828242 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
2024-06-19 07:50:52.828429 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
2024-06-19 07:50:54.828418 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
2024-06-19 07:50:56.828813 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
2024-06-19 07:50:58.829033 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
2024-06-19 07:51:00.829253 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: rst 1518787425 ack 2164524931

 

no still unable to reach host from remote FG to HQ FG.

 

Umirzak
UmirzakAuthor
Visitor III
June 19, 2024

same command tried from remote FG

tengizfg # interfaces=[any]
Unknown action 0

tengizfg # filters=[host 192.168.1.150]
Unknown action 0

tengizfg # 2024-06-19 07:50:40.786918 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
Unknown action 0

tengizfg # 2024-06-19 07:50:42.802375 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
Unknown action 0

tengizfg # 2024-06-19 07:50:44.802757 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
Unknown action 0

tengizfg # 2024-06-19 07:50:46.806683 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
Unknown action 0

tengizfg # 2024-06-19 07:50:48.827926 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
Unknown action 0

tengizfg # 2024-06-19 07:50:50.828242 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
Unknown action 0

tengizfg # 2024-06-19 07:50:52.828429 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
Unknown action 0

tengizfg # 2024-06-19 07:50:54.828418 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
Unknown action 0

tengizfg # 2024-06-19 07:50:56.828813 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
Unknown action 0

tengizfg # 2024-06-19 07:50:58.829033 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: 1518787424 ack 2164524931
Unknown action 0

tengizfg # 2024-06-19 07:51:00.829253 2Tengiz-HQ in 192.168.1.150.445 -> 192.168.50.130.11389: rst 1518787425 ack 2164524931

abarushka
Staff
Staff
June 19, 2024

Hello,

 

I can see that the packet is received "Tengiz-HQ in", however packet is not forwarded. I would recommend to check debug flow output using port 445 as a filter.

sw2090
SuperUser
SuperUser
June 19, 2024

not matching p2 selectors would be seen in Flow Trace log explicitely. The log on the branch only states "denied by forward policy check (policy #0)" which means it got implicitely denied here. This happens either if there is no route to the destination or it did not match any of your policies.

So I'd suggest to check routing and policies on both side.

Umirzak
UmirzakAuthor
Visitor III
June 20, 2024

@abarushka can u help me with the command please

abarushka
Staff
Staff
June 20, 2024

Hello,

 

Here are the commands to collect debug flow:

 

diagnose debug flow filter addr 192.168.1.150
diagnose debug flow filter port 445
diagnose debug flow show function-name enable
diagnose debug flow trace start 100
diagnose debug enable

Umirzak
UmirzakAuthor
Visitor III
June 21, 2024

@abarushka 

uzkfghq # diagnose debug enableid=65308 trace_id=1 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.1.150:445->192.168.50.130:46817) tun_id=89.218.164.118 from 2Tengiz-HQ. flag [.], seq 2917887795, ack 3457127391, win 254"
id=65308 trace_id=1 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, reply direction"
id=65308 trace_id=1 func=vf_ip_route_input_common line=2611 msg="find a route: flag=00000000 gw-192.168.50.130 via internal"
id=65308 trace_id=1 func=npu_handle_session44 line=1206 msg="Trying to offloading session from 2Tengiz-HQ to internal, skb.npu_flag=00000400 ses.state=00000200 ses.npu_state=0x01040001"
id=65308 trace_id=1 func=fw_forward_dirty_handler line=437 msg="state=00000200, state2=00000000, npu_state=01040001"
id=65308 trace_id=2 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.50.130:46817->192.168.1.150:445) tun_id=0.0.0.0 from internal. flag [.], seq 3457127391, ack 2917887796, win 513"
id=65308 trace_id=2 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, original direction"
id=65308 trace_id=2 func=vf_ip_route_input_common line=2611 msg="find a route: flag=04000000 gw-89.218.164.118 via 2Tengiz-HQ"
id=65308 trace_id=2 func=__iprope_tree_check line=528 msg="gnum-100004, use int hash, slot=82, len=2"
id=65308 trace_id=2 func=ipsecdev_hard_start_xmit line=669 msg="enter IPSec interface 2Tengiz-HQ, tun_id=0.0.0.0"
id=65308 trace_id=2 func=_do_ipsecdev_hard_start_xmit line=229 msg="output to IPSec tunnel 2Tengiz-HQ vrf 0"
id=65308 trace_id=2 func=esp_output4 line=896 msg="IPsec encrypt/auth"
id=65308 trace_id=2 func=ipsec_output_finish line=629 msg="send to 89.218.165.137 via intf-wan1"
id=65308 trace_id=3 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.1.150:445->192.168.50.130:46817) tun_id=89.218.164.118 from 2Tengiz-HQ. flag [.], seq 2917887795, ack 3457127391, win 254"
id=65308 trace_id=3 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, reply direction"
id=65308 trace_id=3 func=npu_handle_session44 line=1206 msg="Trying to offloading session from 2Tengiz-HQ to internal, skb.npu_flag=00000400 ses.state=00000200 ses.npu_state=0x01040001"
id=65308 trace_id=3 func=fw_forward_dirty_handler line=437 msg="state=00000200, state2=00000000, npu_state=01040001"
id=65308 trace_id=4 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.50.130:46817->192.168.1.150:445) tun_id=0.0.0.0 from internal. flag [.], seq 3457127391, ack 2917887796, win 513"
id=65308 trace_id=4 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, original direction"
id=65308 trace_id=4 func=ipv4_fast_cb line=53 msg="enter fast path"
id=65308 trace_id=4 func=ipsecdev_hard_start_xmit line=669 msg="enter IPSec interface 2Tengiz-HQ, tun_id=0.0.0.0"
id=65308 trace_id=4 func=_do_ipsecdev_hard_start_xmit line=229 msg="output to IPSec tunnel 2Tengiz-HQ vrf 0"
id=65308 trace_id=4 func=esp_output4 line=896 msg="IPsec encrypt/auth"
id=65308 trace_id=4 func=ipsec_output_finish line=629 msg="send to 89.218.165.137 via intf-wan1"
id=65308 trace_id=5 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.50.130:46817->192.168.1.150:445) tun_id=0.0.0.0 from internal. flag [.], seq 3457127391, ack 2917887796, win 513"
id=65308 trace_id=5 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, original direction"
id=65308 trace_id=5 func=npu_handle_session44 line=1206 msg="Trying to offloading session from internal to 2Tengiz-HQ, skb.npu_flag=00000400 ses.state=00000200 ses.npu_state=0x01040001"
id=65308 trace_id=5 func=fw_forward_dirty_handler line=437 msg="state=00000200, state2=00000000, npu_state=01040001"
id=65308 trace_id=5 func=ipsecdev_hard_start_xmit line=669 msg="enter IPSec interface 2Tengiz-HQ, tun_id=0.0.0.0"
id=65308 trace_id=5 func=_do_ipsecdev_hard_start_xmit line=229 msg="output to IPSec tunnel 2Tengiz-HQ vrf 0"
id=65308 trace_id=5 func=esp_output4 line=896 msg="IPsec encrypt/auth"
id=65308 trace_id=5 func=ipsec_output_finish line=629 msg="send to 89.218.165.137 via intf-wan1"
id=65308 trace_id=6 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.1.150:445->192.168.50.130:46817) tun_id=89.218.164.118 from 2Tengiz-HQ. flag [.], seq 2917887796, ack 3457127515, win 254"
id=65308 trace_id=6 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, reply direction"
id=65308 trace_id=6 func=npu_handle_session44 line=1206 msg="Trying to offloading session from 2Tengiz-HQ to internal, skb.npu_flag=00000400 ses.state=00000200 ses.npu_state=0x01040001"
id=65308 trace_id=6 func=fw_forward_dirty_handler line=437 msg="state=00000200, state2=00000000, npu_state=01040001"
id=65308 trace_id=7 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.50.130:46817->192.168.1.150:445) tun_id=0.0.0.0 from internal. flag [.], seq 3457127515, ack 2917888064, win 512"
id=65308 trace_id=7 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, original direction"
id=65308 trace_id=7 func=ipv4_fast_cb line=53 msg="enter fast path"
id=65308 trace_id=7 func=ipsecdev_hard_start_xmit line=669 msg="enter IPSec interface 2Tengiz-HQ, tun_id=0.0.0.0"
id=65308 trace_id=7 func=_do_ipsecdev_hard_start_xmit line=229 msg="output to IPSec tunnel 2Tengiz-HQ vrf 0"
id=65308 trace_id=7 func=esp_output4 line=896 msg="IPsec encrypt/auth"
id=65308 trace_id=7 func=ipsec_output_finish line=629 msg="send to 89.218.165.137 via intf-wan1"
id=65308 trace_id=8 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.50.130:46817->192.168.1.150:445) tun_id=0.0.0.0 from internal. flag [.], seq 3457127514, ack 2917888064, win 512"
id=65308 trace_id=8 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, original direction"
id=65308 trace_id=8 func=npu_handle_session44 line=1206 msg="Trying to offloading session from internal to 2Tengiz-HQ, skb.npu_flag=00000400 ses.state=00000200 ses.npu_state=0x01040001"
id=65308 trace_id=8 func=fw_forward_dirty_handler line=437 msg="state=00000200, state2=00000000, npu_state=01040001"
id=65308 trace_id=8 func=ipsecdev_hard_start_xmit line=669 msg="enter IPSec interface 2Tengiz-HQ, tun_id=0.0.0.0"
id=65308 trace_id=8 func=_do_ipsecdev_hard_start_xmit line=229 msg="output to IPSec tunnel 2Tengiz-HQ vrf 0"
id=65308 trace_id=8 func=esp_output4 line=896 msg="IPsec encrypt/auth"
id=65308 trace_id=8 func=ipsec_output_finish line=629 msg="send to 89.218.165.137 via intf-wan1"
id=65308 trace_id=9 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.1.150:445->192.168.50.130:46817) tun_id=89.218.164.118 from 2Tengiz-HQ. flag [.], seq 2917888064, ack 3457127515, win 254"
id=65308 trace_id=9 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, reply direction"
id=65308 trace_id=9 func=npu_handle_session44 line=1206 msg="Trying to offloading session from 2Tengiz-HQ to internal, skb.npu_flag=00000400 ses.state=00000200 ses.npu_state=0x01040001"
id=65308 trace_id=9 func=fw_forward_dirty_handler line=437 msg="state=00000200, state2=00000000, npu_state=01040001"
id=65308 trace_id=10 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.50.130:46817->192.168.1.150:445) tun_id=0.0.0.0 from internal. flag [.], seq 3457127514, ack 2917888064, win 512"
id=65308 trace_id=10 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, original direction"
id=65308 trace_id=10 func=ipv4_fast_cb line=53 msg="enter fast path"
id=65308 trace_id=10 func=ipsecdev_hard_start_xmit line=669 msg="enter IPSec interface 2Tengiz-HQ, tun_id=0.0.0.0"
id=65308 trace_id=10 func=_do_ipsecdev_hard_start_xmit line=229 msg="output to IPSec tunnel 2Tengiz-HQ vrf 0"
id=65308 trace_id=10 func=esp_output4 line=896 msg="IPsec encrypt/auth"
id=65308 trace_id=10 func=ipsec_output_finish line=629 msg="send to 89.218.165.137 via intf-wan1"
id=65308 trace_id=11 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.1.150:445->192.168.50.130:46817) tun_id=89.218.164.118 from 2Tengiz-HQ. flag [.], seq 2917888064, ack 3457127515, win 254"
id=65308 trace_id=11 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, reply direction"
id=65308 trace_id=11 func=npu_handle_session44 line=1206 msg="Trying to offloading session from 2Tengiz-HQ to internal, skb.npu_flag=00000400 ses.state=00000200 ses.npu_state=0x01040001"
id=65308 trace_id=11 func=fw_forward_dirty_handler line=437 msg="state=00000200, state2=00000000, npu_state=01040001"
id=65308 trace_id=12 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.1.150:445->192.168.50.130:46817) tun_id=89.218.164.118 from 2Tengiz-HQ. flag [.], seq 2917888063, ack 3457127515, win 254"
id=65308 trace_id=12 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, reply direction"
id=65308 trace_id=12 func=npu_handle_session44 line=1206 msg="Trying to offloading session from 2Tengiz-HQ to internal, skb.npu_flag=00000400 ses.state=00000200 ses.npu_state=0x01040001"
id=65308 trace_id=12 func=fw_forward_dirty_handler line=437 msg="state=00000200, state2=00000000, npu_state=01040001"
id=65308 trace_id=13 func=print_pkt_detail line=5824 msg="vd-root:0 received a packet(proto=6, 192.168.50.130:46817->192.168.1.150:445) tun_id=0.0.0.0 from internal. flag [.], seq 3457127515, ack 2917888064, win 512"
id=65308 trace_id=13 func=resolve_ip_tuple_fast line=5912 msg="Find an existing session, id-0d1b0d2b, original direction"
id=65308 trace_id=13 func=ipv4_fast_cb line=53 msg="enter fast path"
id=65308 trace_id=13 func=ipsecdev_hard_start_xmit line=669 msg="enter IPSec interface 2Tengiz-HQ, tun_id=0.0.0.0"
id=65308 trace_id=13 func=_do_ipsecdev_hard_start_xmit line=229 msg="output to IPSec tunnel 2Tengiz-HQ vrf 0"
id=65308 trace_id=13 func=esp_output4 line=896 msg="IPsec encrypt/auth"
id=65308 trace_id=13 func=ipsec_output_finish line=629 msg="send to 89.218.165.137 via intf-wan1"

 

this export from HQ FG

Umirzak
UmirzakAuthor
Visitor III
June 26, 2024

gents, can u help me, i have 2 sites with IP Sec, HQ can reach branch office e.g.ping, RDP but from branch office to HQ i cannot ping, or even open web server. can u help me what rules i need to check 

Umirzak
UmirzakAuthorAnswer
Visitor III
June 27, 2024

resolved, on branch side the IPSec vpn settings was wrong (Wrong interface)

abarushka
Staff
Staff
July 9, 2024

Hello,

 

Could you please mark it as resolved and latest message as a solution? Therefore, other forum users can benefit. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!