Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hungran91
New Contributor

IP SEC INTERFACE UP. PING AT FORTIGATE DOES'N WORK!

I have 2 FG 60D (local: 192.168.20.254) n 200A (192.168.5.254) using VPN interface mode.

IPsec mornitor is up. I can use RDP, and Local can ping betwen together. I can ping from FG 200A to 192.168.20.254 ok. But i cannot ping from FG 60 to 192.168.5.254 or any device remote site.

PLS help!

 

3 REPLIES 3
ede_pfau
SuperUser
SuperUser

Do you have policies for both directions?


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
hungran91

Yes. On FG 60D i have to use exe ping-options source 192.168.20.254 first then i can ping to 192.168.5.254.
hungran91

hungran91 wrote:
Yes. On FG 60D i have to use exe ping-options source 192.168.20.254 first then i can ping to 192.168.5.254.
But when i logout/login again, it doesnt work. The traffic have only one subnet (192.168.5.0/24) can through over VPN. But on FG 200A i have some static routes. And on FG 60D i was added static routes with device VPN P1 from FG 200A (distance lower than default route).
Labels
Top Kudoed Authors