Created on
11-24-2021
12:34 AM
Edited on
08-09-2022
08:03 PM
By
jiahoong112
Description | This article describes how to take debug in ADVPN when the shortcuts between Spokes do not establish, despite the tunnel being up. |
Scope | FortiOS |
Solution |
If the connectivity between Hub and Spoke is fine, take the IKE debugs to further analyze the details for the ADVPN shortcut.
Take the debug on spoke to collect the shortcut negotiation
FGT SDW 1 # diagnose debug reset
The above IKE debug on Spoke-1 is filtered for multiple IP addresses (mdst-addr4):
It allows capturing the shortcut negotiation between Spoke1↔Hub as well as the shortcut tunnel establishment between Spoke-1↔Spoke-2 Now trigger the shortcut by sending traffic from Spoke-1 source to Spoke-2 destination
Wait for 15 seconds and then stop debug with the help of the below command.
# diagnose debug reset |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.