Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
ORIGINAL: rwpatterson Under ' Router > Monitor' , tell us what it says in either unit. It should show how to get to the other with a valid route. Also in ' VPN > IPSEC > Monitor' , make sure the indicator for your tunnel is green, not red. Red means the tunnel is down.Office 1 Router - Monitor reading as below Type Subtype Network Distance Metric Gateway Interface Up Time Static 0.0.0.0/0 1 0 172.18.113.131 ppp0 Connected 172.18.113.131/32 0 0 0.0.0.0 ppp0 Connected 192.168.0.0/24 0 0 0.0.0.0 internal Office 2 Router - Monitor reading as below Type Subtype Network Distance Metric Gateway Interface Up Time Static 0.0.0.0/0 10 0 203.213.108.249 wan1 Connected 10.10.10.0/24 0 0 0.0.0.0 dmz Connected 192.168.1.0/24 0 0 0.0.0.0 internal Connected 192.168.101.0/24 0 0 0.0.0.0 wan2 Connected 203.213.108.248/29 0 0 0.0.0.0 wan1 the indicator in IPSec Monitor is RED SO IT IS NOT working.
regards
/ Abel
Office 1 Router - Monitor reading as below Type Subtype Network Distance Metric Gateway Interface Up Time Static 0.0.0.0/0 1 0 172.18.113.131 ppp0 Connected 172.18.113.131/32 0 0 0.0.0.0 ppp0 Connected 192.168.0.0/24 0 0 0.0.0.0 internal Office 2 Router - Monitor reading as below Type Subtype Network Distance Metric Gateway Interface Up Time Static 0.0.0.0/0 10 0 203.213.108.249 wan1 Connected 10.10.10.0/24 0 0 0.0.0.0 dmz Connected 192.168.1.0/24 0 0 0.0.0.0 internal Connected 192.168.101.0/24 0 0 0.0.0.0 wan2 Connected 203.213.108.248/29 0 0 0.0.0.0 wan1Most of us (I believe) configure our tunnels in interface mode. When doing that, you have the option of giving the interface an IP address. When you do this, you can then point a static route between boxes directly. Once you have done it this way, you' ll probably never go back to the policy based tunnel setup again. I haven' t. For example the subnetwork between routers would be 172.16.1.0/29. The IPSEC interface on router 1 would be 172.16.1.1, and router 2 would be 172.16.1.2. From office 1, add a static route of
static, 192.168.1.0/24, distance 1, Metric 1, gateway 172.16.1.2, rtr 1 interface nameFrom office 2, add a static route of
static, 192.168.0.0/24, distance 1, Metric 1, gateway 172.16.1.1, rtr 2 interface nameDone.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1789 | |
1120 | |
768 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.