VPN tunnel UP but only one way initiation of traffic
We try to setup a IPsec tunnel between a Fortigate 100D and a Fortigate 3016B. Software version for the 100D is FortiOS5.0 Patch 4, the 3016B is using FortiOS4.0 Patch 15. Everything looks fine, tunnel is coming up (In Webgui, IPsec-Monitor) But traffic is only passing if initiated from one site (the 100D side)
So, if we ping from a server behind the 100D we are getting a response from the server on the other site. If We try this within approx. 10 min. ping from behind the 3016 is also successfull.
If try to ping from behind the 3016B after an amount of time (more then 10 a 15 minutes) we couldn't ping succesfull from a server behind the 3016B to a server behind the 100D.
(So If we initiate form behind the 100D also traffic initiated from behind the 3016B will allowed.
We have checked the configs multiple times and they are the same. Also on both Fortigates we have two policies, one from the tunnel-interface to LAN and vice-versa.
(We are using Interface mode IPsec)
Is this a known issue or compatibility problem between the fortigates/software versions? (For both units others tunnels are working fine.
We are using AES128/SHA1 for auhtentication and encryption.
I hope you can help and we can solve this problem.
