Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JP57
New Contributor II

FG to Sierra Wireless XR80 IPSec VPN

Has anyone successfully created an IPSec VPN tunnel between a FG on a Sierra Wireless XR80/90?

 

I've created a tunnel, routes, and policies successfully, but can't get communication across the tunnel.

Tried Sierra Wireless's documentation too, with no success.

https://source.sierrawireless.com/airlinkos/XR80-4.1/reference/networking/howto/vpn/

Like I said, the tunnel is up, but can NOT get traffic to flow across.

1 Solution
JP57
New Contributor II

Might have been related to the cellular service plan we had the XR80 on.  Switched it over to their Fixed Wireless plan and then it worked.  Made no other changes to the FG.

View solution in original post

4 REPLIES 4
TuncayBAS
Contributor II

Can you initiate a ping from a PC behind Fortigate to a PC behind Sierra and get a debug?

You must make sure that the packet enters the VPN.

 

for example:


Let the PC behind FGT be: 192.168.1.100
PC running Sierra: Let it be 192.168.3.200

 

dia debug flow filter addr 192.168.3.200
dia debug flow trace start 100
dia debug en

 

When you start a ping to 192.168.3.200, the debug logs that appear on the screen may contain messages that will help you understand the problem.

 

Tuncay BAS RZK Muhendislik Turkey NSE 4 5 6 FCESP v5

Tuncay BAS RZK Muhendislik Turkey NSE 4 5 6 FCESP v5
JP57
New Contributor II

Might have been related to the cellular service plan we had the XR80 on.  Switched it over to their Fixed Wireless plan and then it worked.  Made no other changes to the FG.

mle2802
Staff
Staff

Hi @JP57,

Is the tunnel up when using cellular service? You can try to switch back and run debug flow commands on FortiGate to see if traffic flowing through the tunnel:

diag debug reset
diag debug flow filter addr X.X.X.X (source IP)
diag debug flow filter proto 1
diag debug flow show ip en
diag debug flow show func en
diag debug console time ena
diag debug ena
diag debug flow trace start 999

Regards,
Minh

parteeksharma

Dear JP57,
Please check if the traffic is hitting to the correct policy and route is present on firewall to point the interesting traffic to flow across correct IPsec tunnel.

Regards,
Parteek

Labels
Top Kudoed Authors