Skip to main content
RDY77
New Member
October 8, 2020
Question

VPN IPSEC phase 2 with secondary lan subnet

  • October 8, 2020
  • 2 replies
  • 2687 views

Hello all.

I'm facing a problem with VPN IPSEC.

On the LAN interface I've two addressing, primary and secondary, and I would put into the encryption domain of the phase 2, the secondary subnet.

It seems all fine; phase 2 goes UP, but the traffic doesn't pass through the tunnel. Routing is correct.

Instead, if I configure primary subnet, it works perfectly as expected.

Do you know why?

    2 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    October 8, 2020

    Check route&policy on both sides of the tunnel. Then run sniff to see which side is dropping and run "flow debug" on the dropping side.

    RDY77
    RDY77Author
    New Member
    October 8, 2020

    Very strange!

    After I wrote it worked.

    I restarded the FGT and done againg the VPN configuration; I see the route for the secondary subnet, the phase 2 come up and the traffic passes.

    Sorry and thx.