Skip to main content
MustphaBassim
New Member
March 11, 2023
Question

VTI interface issue

  • March 11, 2023
  • 6 replies
  • 3420 views

Hello Dears

 

I had setup an ipsec tunnel between two Fortigate Firewalls , the tunnel is UP i am trying to create VTI interface on them so i had added an ip address on both devices on tunnel interfaces but i could not get reachablity (point to point) between them

 

T1 10.126.0.1 (FG1)

T1 10.126.0.2 (FG2)

where T1 is the tunnel interface on both devices

 

Best Regards

6 replies

Contributor III
March 11, 2023

Hello,

 

Can you share the interface route and tunnel details from both devices? Also, you'll need to add the tunnel interface IP in the phase 2  traffic selector if you've configured some specific phase 2  traffic selector.


show system interface <Name>
get router info routing-table details x.x.x.x
diag vpn tunnel list
diag vpn ike gateway list
get vpn ipsec tunnel summary

MustphaBassim
New Member
March 11, 2023

Hello Dear
after adding them to selector , now the ping is ok but unable to perferom OSPF adjecancy to the end node,Untitled.pngUntitled2.pngUntitled3.png

Contributor III
March 11, 2023

Hello,

 

Please follow the below guide and verify the OSPF configuration.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-OSPF-with-IPSec-VPN-for-network-redundancy/ta-p/190111

If the configuration is fine share the below output:

get router info ospf neighbor
get router info ospf status
get router info ospf interface

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!