Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Lucas1
New Contributor II

Execute Backup does not reach a remote site connected by ipsec.

I am having a problem running an automation to backup my computer. I want to send the backup to a sftp server of a remote branch, connected to the fortigate equipment from which I make the backup, and it is as if it did not arrive. If I do a ping it arrives, but I have to specify the source. Does anyone have any idea how I can fix it?

The traffic and routes are allowed on both sides. But when I launch the "execute backup" it doesn't arrive. When pinging I have to add the source option to allow the traffic.

 

Packet Trace #7,2024/08/06 15:59:27,"vd-root:0 received a packet(proto=6, 181.14.198.42:6817->10.1.4.121:22) tun_id=0.0.0.0 from local. flag [S], seq 4203643946, ack 0, win 65535"
Packet Trace #7,2024/08/06 15:59:27,"Find an existing session, id-060b7b91, original direction"
Packet Trace #7,2024/08/06 15:59:27,"enter IPSec interface VPN_IPSec1, tun_id=0.0.0.0"
Packet Trace #7,2024/08/06 15:59:27,output to IPSec tunnel VPN_IPSec1 vrf 0
Packet Trace #7,2024/08/06 15:59:27,"No matching IPsec selector, drop"

1 Solution
jguerra
Staff
Staff

Hi Lucas, sometimes is necessary to configure an IP address in the Ipsec tunnel interfaces for this configuration to work. See the KB below:

 

Technical Tip: Configure automation backup over IPsec tunnel 

View solution in original post

4 REPLIES 4
patelr
Staff
Staff

Hello @Lucas1

 

Please review https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPN-tunnel-errors-due-to-traff... as your debug says "No matching IPsec selector, drop" , which mean phase-2 configurations aren't matching on both sides. Make sure, all phase-2 configurations should be matched on Local, and remote firewall device.

 

Thanks, 

Ronak Patel

jguerra
Staff
Staff

Hi Lucas, sometimes is necessary to configure an IP address in the Ipsec tunnel interfaces for this configuration to work. See the KB below:

 

Technical Tip: Configure automation backup over IPsec tunnel 

Lucas1
New Contributor II

Excellent. This is the answer I was looking for. I will give it a try and see how it goes. Thank you very much.

Umer221
Staff
Staff

Hi Lucas,

 

If the Backup server is hosted across the IPsec Tunnel, then you will need to define a source IP address on the FortiGate from where the backup is being initiated. Here is an article that would provide further details regardless of the backup services vendor:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Auvik-backup-fails-while-Auvik-serve...

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors