This seems like I've missed something real basic here. I've got two Fortigates connected to each other over an IPSec VPN through the internet. One at my remote office and one at the main office. Clients on both sides can communicate with each other without any problems however I cannot get the remote firewall itself to send data (or ping) a FortiAnalyzer on the side of my main office network. Based on flow/packet traces and the remote firewall logs, the packets don't seem to be traversing the VPN tunnel and seem to be just going out the Internet/WAN interface which of course are blocked by the Internet interface on the main branch firewall.
I'm at a loss considering the clients on the remote side can hit addresses on the main office side. Any ideas? L
-Mike
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I believe it's to do with the SRC address.
On the remote FGT side you can try change the FGT's source address to it's internal network IP address.
config log fortianalyzer setting
set source-ip <FGTs internal IP address>
end
Same thing happens with the ping. You can change the source IP address when you try to ping from the FGT.
execute ping-options source <FGTs internal IP address>
execute ping <remote FAZ>
neonbit wrote:I believe it's to do with the SRC address.
On the remote FGT side you can try change the FGT's source address to it's internal network IP address.
config log fortianalyzer setting
set source-ip <FGTs internal IP address>
end
Same thing happens with the ping. You can change the source IP address when you try to ping from the FGT.
execute ping-options source <FGTs internal IP address>
execute ping <remote FAZ>
That worked perfectly! Thanks!
-Mike
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1632 | |
1063 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.