Hi All,
I have followed the video at
http://video.fortinet.com/video/102/site-to-site-ipsec-vpn-behind-firewall-nat-device
on how to setup a dial up IPSEC VPN (Branch to HQ) where branch firewall is behind a router doing NAT. HQ are Dial up server and branch is dial up client.
I have been able to setup the IPSEC VPN (it comes up). From the branch FortiGate using console I can ping (with execute ping) hosts on HQ LAN. Viceversa, I can ping hosts on the Branch LAN from the HQ Fortigate console (so I believe I am close to achieving the result). What does not work is a ping from hosts to and from HQ LAN and Branch LAN.
Things are different on FortiOS4.0MR3 so one cannot setup the static routing as shown in the video since the IPSEC VPN does not show up as an interface.
Any hints on how to do this ?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The diag debug flow would shed some light on the issue(s).
e.g assuming the branch lan host of 1.1.1.1
diag debug reset
diag debug dis
diag debug enable
diag debug flow filter addr 1.1.1.1
diag debug flow filter proto 1
diag debug flow show console enable
diag debug flow trace start 100
And after the conculsion
diag debug dis
Your problems could be lack of routes, incorrect firewall policies or sequences of NAT enabled on a policy that does not need nat.
PCNSE
NSE
StrongSwan
SOLVED : In OS 4.0 , when defining IPSEC Phase 1 (in the GUI) one has to select the Interface Mode check box (possible only when creating the phase 1). This makes the VPN tunnel available as an interface in the list of interfaces. From here on the steps outlined in the video are identical and it works !!!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.