Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
itc
New Contributor II

GRE Tunel not working after 7.4.1 > 7.4.3

Hi

My GRE tunel connection is not working after upgrade FortiOS from 7.4.1 > 7.4.3.

Forti shows, that connection is UP but I have no access  to network. 

Checked policies, diagnosed connection and everything looks fine.

Any idea what to check next? How to monitor?

 

Best regards,

Rafal

34 REPLIES 34
hbac

Hi @Deltaman,

 

Are you using IP pool in the firewall policy of GRE tunnel? 

 

Regards, 

Deltaman
New Contributor II

No, just 1 public IP on my PPPOE interface. (NATted on interface without the use of an IP pool)

 

I use NAT because my GRE tunnel comes from a VDOM via VDOM link.

Kangming

What model is your FGT? Can you share the configuration file or ticket id?

 

Thanks

Kangming

itc
New Contributor II

After lamost 7h with Fortinet Suppoert on hands in my case none of above worked and end-up with conclusion: bug moved to Enginers to wrok it out, and meanwhile downgrade to 7.4.1.:

------------------------------------

anti-spoof check failed,drop

------------------------------------

Log entry causes problems and no one have any idea, for now, WHY.
Wait.. Fortinet: We are developing 7.4.4 - wait... 
 
No solution for this so far...
If any changes came up, I will let You all know.
 
Best regards
 

 

AEK

@itc, thanks for sharing

anti-spoof check fail should mean FG has no route back to the sending IP. This consolidates @Deltaman 's observation that GRE route not added to routing table.

In that case, adding manually the route should be a good workaround.

AEK
AEK
hbac

@itc,

 

If you are staying on 7.4.1, please make sure to disable SSLVPN to as it is vulnerable. https://www.fortiguard.com/psirt/FG-IR-24-015

 

Regards, 

kaskipl
New Contributor II

Hello

 

Does anyone know when the GRE problem will be fixed approximately?

 

Regards,

Kangming
Staff
Staff

What model is your FGT? Can you share the configuration file or ticket id?

 

Thanks

Kangming

kaskipl
New Contributor II

Hello Kangming

 

My FG is FGVM64, I have the same problem as @infor1.


After updating to 7.4.3 due to the vulnerability in SSLVPN, the logs
are showing: "anti-spoof check failed,drop"


None of the solutions found worked.


Local support provided information similar to that obtained by @itc.

 

I'm still patiently waiting for the new FortiOS to solve this.
Hence my question if anyone already knows an approximate term.

 

Regards,

AEK

Hello @kaskipl 

anti-spoof check fail means the FG doesn't have route back to the sending IP. I think GRE is somehow not pushing the route to the routing table.

Can you try add manually the related static route to the FG once GRE is established?

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors