Hi
My GRE tunel connection is not working after upgrade FortiOS from 7.4.1 > 7.4.3.
Forti shows, that connection is UP but I have no access to network.
Checked policies, diagnosed connection and everything looks fine.
Any idea what to check next? How to monitor?
Best regards,
Rafal
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Created on 02-15-2024 12:25 AM Edited on 02-15-2024 12:33 AM
No, just 1 public IP on my PPPOE interface. (NATted on interface without the use of an IP pool)
I use NAT because my GRE tunnel comes from a VDOM via VDOM link.
What model is your FGT? Can you share the configuration file or ticket id?
Thanks
Kangming
After lamost 7h with Fortinet Suppoert on hands in my case none of above worked and end-up with conclusion: bug moved to Enginers to wrok it out, and meanwhile downgrade to 7.4.1.:
------------------------------------
anti-spoof check failed,drop
------------------------------------
@itc,
If you are staying on 7.4.1, please make sure to disable SSLVPN to as it is vulnerable. https://www.fortiguard.com/psirt/FG-IR-24-015
Regards,
Hello
Does anyone know when the GRE problem will be fixed approximately?
Regards,
What model is your FGT? Can you share the configuration file or ticket id?
Thanks
Kangming
Created on 03-11-2024 10:31 PM Edited on 03-11-2024 10:34 PM
Hello Kangming
My FG is FGVM64, I have the same problem as @infor1.
After updating to 7.4.3 due to the vulnerability in SSLVPN, the logs
are showing: "anti-spoof check failed,drop"
None of the solutions found worked.
Local support provided information similar to that obtained by @itc.
I'm still patiently waiting for the new FortiOS to solve this.
Hence my question if anyone already knows an approximate term.
Regards,
Hello @kaskipl
anti-spoof check fail means the FG doesn't have route back to the sending IP. I think GRE is somehow not pushing the route to the routing table.
Can you try add manually the related static route to the FG once GRE is established?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.