We have an IPsec VPN between FortiGate 60E and SonicWall NSA 2600. The VPN is up and active but no traffic is passing across it.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
What does your routing table look like?
Fortigate # diagnose ip route list
Blank out any unimportant routes to this thread that you may not want made public.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Yes, phase 1 and 2 are up. Already verified that beforehand and verified again
Did you at least do "diag debug flow" ? It will tell you everything that is wrong or what's happening.
You have to help us in order to help you.
Also patterson mention traceroute earlier. I would also add "diag sniffer packet" and select the tunnel interface name that you use in phase1 and witness the traceroute enter/exit the tunnel
That would confirm traffic in the tunnel assuming a route-based and you run traceroutes from A and Z sides.
http://socpuppet.blogspot.com/2013/10/site-2-site-routed-vpn-trouble-shooting.html
Ken Felix
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1717 | |
1093 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.