Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hersiguure
New Contributor

Fortigate200D-Fortigate800C Site-to-site VPN Setup

Hello,

 

I have configured site to site vpn between Fortigate 200D-800C, and the  tunnel is up, but there is no 

traffic going out and coming in, after investigating by capturing the icmp traffic, I found that the source address traffic is coming from the Management Interface rather than the required LAN Port 1.

 

please help

Thanks

Ahmed

1 Solution
rwpatterson
Valued Contributor III

Make sure the distance is less than that of your default gateway. 10 is the usual distance for the default which is the same as your tunnel traffic. Make the tunnel traffic anything lower. I use 5 myself.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

View solution in original post

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
8 REPLIES 8
gschmitt
Valued Contributor

Did you remember to create policies to allow incoming and outgoing traffic on both sides?

Do you have static routes pointing to the IPSec Tunnels?

hersiguure
New Contributor

Hi gschmitt,

 

I have created both incoming and outgoing policies for fortigate firewalls, also i have created a static route pointing to Phase 1 Interface,

 

THanks

 

emnoc
Esteemed Contributor III

The diag debug flow is your best friend here. Apply a filter to match on your traffic and review the diagnostic output.

 

A few things to look for, bad fw-policies, bad ordering or sequence of fw-policies, phase#2 is not up, PBR over-ridding the static route(s),etc....

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
hersiguure

Emnoc,

I have ordered the fw-policies as follows

Incoming Policy

Phase 1 interface -- Remote-LAN --- Local Port --- Local LAN

Outgoing

Local Port --- Local LAN ---- Phase 1 Interface --- Remote LAN, 

Also static route is as followss

Destination Network --- Device(Phase 1 Interface), Distance 10

and phase 2 up 

 

 

rwpatterson
Valued Contributor III

Make sure the distance is less than that of your default gateway. 10 is the usual distance for the default which is the same as your tunnel traffic. Make the tunnel traffic anything lower. I use 5 myself.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
hersiguure

Hello Team,

Thanks, It worked,

 

Valuable tips that helped me

1. lowering static rule distance 

2. sequencing the fw-policies

 

 

Ahmed

rwpatterson
Valued Contributor III

Nice to know "I still got it!"

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
emnoc
Esteemed Contributor III

diag debug flow

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors