Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
khalilbouzaiene1
Contributor

I am experiencing a loss of ICMP sessions when I attempt to ping through the IPsec tunnel.

hello guys 

I have established a site-to-site (S2S) tunnel with two FortiGate firewalls, and this is my topology.

 

topologie.png

then the tunnel work but no perfectly it can ping juste from the interface of the lan to the other lan interface (and vise verca) (exmple : ping from 192.168.1.1 to 10.0.0.1 it works but if we want to ping from the to the other host the ping issue )
after some time of troubleshooting i find out that the icmp session losed in evry icmp request 
debug1.pngdebug2.pngdebug3.png

so guys  what is the solution for this problem please !

21 REPLIES 21
khalilbouzaiene1

@smaruvala  here an other test that i have done also 
i try to ping from the lan interface of the fortugate FW-A (192.168.1.1) to the host 10.0.0.2 to ensure that the packet will arrived to FW-A because when we try to ping from lan interface to the other lan interface of the frotigate the ping work and pass throw the tunnel (192.168.1.1 to 10.0.0.1) 

so write in the terminal of the FW-A like this  

FW-A # execute ping-options source 192.168.1.1

FW-A # execute ping 10.0.0.2
PING 10.0.0.2 (10.0.0.2): 56 data bytes

--- 10.0.0.2 ping statistics ---
5 packets transmitted, 0 packets received, 100% packet loss

 

 

 

so this snapshot was taked in fortigate FW-B  to capture the packet arrived 
pack.pngpack2.png

 

 

here we can say that from the FW-B he can't find a route to the host or what ????

khalilbouzaiene1

also i disabled windows firewall to allow ping

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors