Hi,
I have 3 FortiExtenders (FXT311F-v7.4.6-build25) connecting to my FortiGate 100F (7.4.7 build 2731)via their lte1 interface. They are all showing in the FortiExtenders section - can see their wan ip address and perform basic diagnostics. The are all using the default lan extension profile and ipsec tunnel.
I have policies configured to enable them to access my local lan etc.
The problem is that the IPSEC Tunnel just never comes up - there is very little information out there relating to the Extenders so hoping someone on here can shed some light on how to fix this issue.
Regards
Hi Gokiwi64,
Thank you for using our forums. Others can likely answer your question in more detail, but it looks like these articles may be relevant to your query - please let me know if they help (or if they don't!)
Created on 09-05-2025 02:49 AM Edited on 09-05-2025 03:39 AM
Hi,
I have the same problem but I can see on console port of the FEX that it has gotten an IPsec configuration from the FortiGate. When I look on the FortiGate, I see that the IPsec configuration for the FEX is missing.
As the documtent https://docs.fortinet.com/document/fortiextender/7.6.0/troubleshooting-guide/21290/fortigate-managed... states that "The FortiGate should also be able to ping back to FortiExtender." which could be problematic. Since I also do use the lte interface for an internet connection on the FEX. We all know that mobile networks are heavily behind NAT. Which means the FortiGate can't start a session from itself, only if the FortiExtender starts first.
NAT mode is on and IKE port ist 500 on the FEX. Should I change the port to 4500?
Tbh, you posted that all 3 of your FEX are already connected to the FGT via VPN, and that you can pull data from them. Next sentence states that the VPN never comes up. Could you please clarify?
If you post the VPN config (ph1 + ph2) of the FEX and the FGT here, we can check it for you. Make sure the FEX does have a default route to the internet, to be able to contact the FGT's WAN port.
Re-check the operating mode of the FEX - it needs to be in "NAT mode" for the IPsec VPN to work.
And, last advice, which details differ in the FEX configs if only one of them doesn't work? Or are all 3 non-operational?
Apologies for the confusion !!.
The FEX's are connecting to the FortiGate - (If I knew how to add pictures I could show that) . However the associated IPSEC tunnel never comes up. So a laptop eg connected to an interface on the FEX cannot connect to my office resources.
So although the laptop gets a dhcp address from the FEX it doesnt connect to anything.
I hope that makes more sense ?
Regards
User | Count |
---|---|
2549 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.