Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gokiwi64
New Contributor

FortiExtender - FortiGate 100F IPSec tunnel not coming up

Hi,

I have 3 FortiExtenders (FXT311F-v7.4.6-build25) connecting to my FortiGate 100F (7.4.7 build 2731)via their lte1 interface. They are all showing in the FortiExtenders section - can see their wan ip address and perform basic diagnostics. The are all using the default lan extension profile and ipsec tunnel.

I have policies configured to enable them to access my local lan etc.

The problem is that the IPSEC Tunnel just never comes up  - there is very little information out there relating to the Extenders so hoping someone on here can shed some light on how to fix this issue.

 

Regards

4 REPLIES 4
Stephen_G
Moderator
Moderator

Hi Gokiwi64,

 

Thank you for using our forums. Others can likely answer your question in more detail, but it looks like these articles may be relevant to your query - please let me know if they help (or if they don't!)

Stephen - Fortinet Community Team
MG4
New Contributor III

Hi,

I have the same problem but I can see on console port of the FEX that it has gotten an IPsec configuration from the FortiGate. When I look on the FortiGate, I see that the IPsec configuration for the FEX is missing. 

As the documtent https://docs.fortinet.com/document/fortiextender/7.6.0/troubleshooting-guide/21290/fortigate-managed...  states that "The FortiGate should also be able to ping back to FortiExtender." which could be problematic. Since I also do use the lte interface for an internet connection on the FEX. We all know that mobile networks are heavily behind NAT. Which means the FortiGate can't start a session from itself, only if the FortiExtender starts first.

 

NAT mode is on and IKE port ist 500 on the FEX. Should I change the port to 4500?

ede_pfau
SuperUser
SuperUser

Tbh, you posted that all 3 of your FEX are already connected to the FGT via VPN, and that you can pull data from them. Next sentence states that the VPN never comes up. Could you please clarify?

 

If you post the VPN config (ph1 + ph2) of the FEX and the FGT here, we can check it for you. Make sure the FEX does have a default route to the internet, to be able to contact the FGT's WAN port.

 

Re-check the operating mode of the FEX - it needs to be in "NAT mode" for the IPsec VPN to work.

 

And, last advice, which details differ in the FEX configs if only one of them doesn't work? Or are all 3 non-operational?

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
gokiwi64

Apologies for the confusion !!.

The FEX's are connecting to the FortiGate   - (If I knew how to add pictures I could show that) . However the associated IPSEC tunnel never comes up. So a laptop eg connected to an interface on the FEX cannot connect to my office resources.

So although the laptop gets a  dhcp address from the FEX it doesnt connect to anything.

I hope that makes more sense ?

 

Regards

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors