Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mgambacorta
New Contributor

Dial up ipsec with FortiOS 4.0 MR3

Hi All,

 

I have followed the video at 

http://video.fortinet.com/video/102/site-to-site-ipsec-vpn-behind-firewall-nat-device

 

on how to setup a dial up IPSEC VPN (Branch to HQ) where branch firewall is behind a router doing NAT. HQ are Dial up server and branch is dial up client.

 

I have been able to setup the IPSEC VPN (it comes up). From the branch FortiGate using console I can ping (with execute ping) hosts on HQ LAN. Viceversa, I can ping hosts on the Branch LAN from the HQ Fortigate console (so I believe I am close to achieving the result). What does not work is a ping from hosts to and from HQ LAN and Branch LAN. 

 

Things are different on FortiOS4.0MR3 so one cannot setup the static routing as shown in the video since the IPSEC VPN does not show up as an interface.

 

Any hints on how to do this ?

2 REPLIES 2
emnoc
Esteemed Contributor III

The diag debug flow would shed some light on the issue(s).

 

e.g assuming the branch lan host of 1.1.1.1

 

 

diag debug reset

diag debug dis

diag debug enable

diag debug flow filter addr 1.1.1.1

diag debug flow filter proto 1

diag debug flow show console enable

diag debug flow trace start  100

 

And after the conculsion

 

diag debug  dis

 

Your problems could be lack of routes, incorrect firewall policies or sequences of NAT enabled on a policy that does not need nat.

 

 

 

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
mgambacorta
New Contributor

SOLVED : In OS 4.0 , when defining IPSEC Phase 1 (in the GUI) one has to select the Interface Mode check box (possible only when creating the phase 1). This makes the VPN tunnel available as an interface in the list of interfaces. From here on the steps outlined in the video are identical and it works !!!

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors