Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hungran91
New Contributor

IP SEC INTERFACE UP. PING AT FORTIGATE DOES'N WORK!

I have 2 FG 60D (local: 192.168.20.254) n 200A (192.168.5.254) using VPN interface mode.

IPsec mornitor is up. I can use RDP, and Local can ping betwen together. I can ping from FG 200A to 192.168.20.254 ok. But i cannot ping from FG 60 to 192.168.5.254 or any device remote site.

PLS help!

 

3 REPLIES 3
ede_pfau
SuperUser
SuperUser

Do you have policies for both directions?

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
hungran91

Yes. On FG 60D i have to use exe ping-options source 192.168.20.254 first then i can ping to 192.168.5.254.
hungran91

hungran91 wrote:
Yes. On FG 60D i have to use exe ping-options source 192.168.20.254 first then i can ping to 192.168.5.254.
But when i logout/login again, it doesnt work. The traffic have only one subnet (192.168.5.0/24) can through over VPN. But on FG 200A i have some static routes. And on FG 60D i was added static routes with device VPN P1 from FG 200A (distance lower than default route).
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors