Hello,
I have configured site to site vpn between Fortigate 200D-800C, and the tunnel is up, but there is no
traffic going out and coming in, after investigating by capturing the icmp traffic, I found that the source address traffic is coming from the Management Interface rather than the required LAN Port 1.
please help
Thanks
Ahmed
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Make sure the distance is less than that of your default gateway. 10 is the usual distance for the default which is the same as your tunnel traffic. Make the tunnel traffic anything lower. I use 5 myself.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Did you remember to create policies to allow incoming and outgoing traffic on both sides?
Do you have static routes pointing to the IPSec Tunnels?
Hi gschmitt,
I have created both incoming and outgoing policies for fortigate firewalls, also i have created a static route pointing to Phase 1 Interface,
THanks
The diag debug flow is your best friend here. Apply a filter to match on your traffic and review the diagnostic output.
A few things to look for, bad fw-policies, bad ordering or sequence of fw-policies, phase#2 is not up, PBR over-ridding the static route(s),etc....
PCNSE
NSE
StrongSwan
Emnoc,
I have ordered the fw-policies as follows
Incoming Policy
Phase 1 interface -- Remote-LAN --- Local Port --- Local LAN
Outgoing
Local Port --- Local LAN ---- Phase 1 Interface --- Remote LAN,
Also static route is as followss
Destination Network --- Device(Phase 1 Interface), Distance 10
and phase 2 up
Make sure the distance is less than that of your default gateway. 10 is the usual distance for the default which is the same as your tunnel traffic. Make the tunnel traffic anything lower. I use 5 myself.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Hello Team,
Thanks, It worked,
Valuable tips that helped me
1. lowering static rule distance
2. sequencing the fw-policies
Ahmed
Nice to know "I still got it!"
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
diag debug flow
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.