Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hbuenafe81
New Contributor III

Fortigate ipsecvpn s2s policy not working but reverse path policy is OK.

Gents,

 

Need some help here.. I setup s2s. Tunnel is up and both p1 and p2 are up, however I encounter issue. Customer can't reach my loopback ip but loopback ip can reach and ping customer ip. 

 

I've attached diagram and log result for everyone's information. Maybe I missed something here. Btw, it was working on 1st day and suddenly stop. 

 

A kind support is highly appreciated.

diagram and log resultdiagram and log result

Regards

HB

TBogs
TBogs
1 Solution
ozkanaltas
Valued Contributor II

Hello @hbuenafe81 ,

 

Which version do you use? 

 

Can you disable the arp reply on these VIP objects?

 

config firewall vip
    edit <VIP_NAME>
        set arp-reply disable
    next
end
If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
12 REPLIES 12
hbuenafe81

Apology for the late response, yes there is.. some policy VIP/NAT use to loopback ip 

TBogs
TBogs
ozkanaltas
Valued Contributor II

Hello @hbuenafe81 ,

 

Which version do you use? 

 

Can you disable the arp reply on these VIP objects?

 

config firewall vip
    edit <VIP_NAME>
        set arp-reply disable
    next
end
If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
hbuenafe81

WOOW... Thanks much Ozkanaltas appreciate much it solve the issue. I delete the vip that relate to 10.2.202.10.. but its weird coz i only created that vip without implementing it to the policy object as in it 0 ref. Once again appreciated you help. Version use is 7.2.8  

TBogs
TBogs
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors