Description | This article describes how to troubleshoot one-way traffic over the IPSec tunnel between 2 FortiGates. |
Scope | FortiGate. |
Solution |
Topology:
The machine on subnet 10.122.0.0/20 can reach (ping) devices on subnet 10.171.0.0/20, but not the other way around.
Example:
dia de flow filter addr 10.171.0.10 10.122.0.10 and <----- This will capture traffic from and to these 2 addresses.
To disable:
dia deb disable dia deb reset
3. Packet capture on FGT-B:
Related articles: Technical Tip: Source IP for self-originating IPsec tunnel traffic |