We have an IPsec VPN between FortiGate 60E and SonicWall NSA 2600. The VPN is up and active but no traffic is passing across it.
What does your routing table look like?
Fortigate # diagnose ip route list
Blank out any unimportant routes to this thread that you may not want made public.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Yes, phase 1 and 2 are up. Already verified that beforehand and verified again
Did you at least do "diag debug flow" ? It will tell you everything that is wrong or what's happening.
You have to help us in order to help you.
Also patterson mention traceroute earlier. I would also add "diag sniffer packet" and select the tunnel interface name that you use in phase1 and witness the traceroute enter/exit the tunnel
That would confirm traffic in the tunnel assuming a route-based and you run traceroutes from A and Z sides.
http://socpuppet.blogspot.com/2013/10/site-2-site-routed-vpn-trouble-shooting.html
Ken Felix
PCNSE
NSE
StrongSwan
User | Count |
---|---|
2052 | |
1170 | |
770 | |
448 | |
341 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.