I have tried to create a VPN connection from a device connected to a fortinet wireless AP to a device connected to another port on the Fortigate. I have managed to successfully get an IPSec VPN connection, but when connected, i can not ping the other device. Here are the current policies I have in place in an attempt to achieve this:
Outbound Policy (SSID to Internal):
Inbound Policy (Internal to SSID):
IPSec Policy (IPSec to Internal):
When i try ping the internal network interface, i get "request timed out". I can only ping as far as the AP interface. There is the port interface that the AP connects to so my next step is to look at what policies may need to be applied using this interface. Any help is greatly appreciated.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The following may help you in troubleshooting:
Double-check your policies for the port interface the AP is connected to. Also, any chance there's a firewall on the AP itself causing the timeout?
Hi @ABE_63,
Please run debug flow to see if the traffic is being dropped. https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...
Example (Replace x.x.x.x with destianation IP):
di deb disable
di deb res
diagnose debug flow filter clear
di deb flow filter addr x.x.x.x
di deb flow filter proto 1
diagnose debug flow show function-name enable
di deb flow show iprope en
diagnose debug console timestamp enable
diagnose debug flow trace start 500
diagnose debug enable
Regards,
hi @ABE_63,
Can you try to run a sniffer to see packet is flowing using the command diag sniffer packet any "host X.X.X.X and icmp" 4 0 l
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.