we have a site to site tunnel through which we are able to connect to all the instances behind the firewall but cannot SSH, Ping or Https to the firewall. Can you help by sharing how to get management access over a vlan interface through IPSEC. Services are enabled on the interface.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
In general, you need to check these things:
- Enabled management on interface - allow ping, HTTPS, SSH
- Allow traffic from Ipsec tunnel to this interface - including these service
- Verify that no local-in policy is configured that could block the traffic
- If under administrators, you have trusted host/network configured, add subnet/host that you are trying to connect to it.
If all this looks good, do simple debug flow on that device and it will at least tell you direction which you should look. If you will see message like this "iprope_in_check() check failed, drop" it means that FortiGate is blocking it.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1720 | |
1094 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.