Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
woodJT
New Contributor

IPSEC - ONE WAY PING

Hi Fellows,

I have configured a simple ipsec tunnel hub to 1x spoke hoping to add more spokes later on.

the ipsec tunnel is dial up based with peertyp any . the tunnel is up and can ping the local subnet behind the hub from the remote subnet behind the spoke but not the opposite direction .

I assigned IP to the tunnel interfaces and I can ping only direction [spoke to hub but not hub to spoke]

I triple checked the static routes and firewall policies and all look fine. 

am I missing anything ?

 

SPOKE TO HUB PING

# execute ping 192.168.2.11
PING 192.168.2.11 (192.168.2.11): 56 data bytes
64 bytes from 192.168.2.11: icmp_seq=0 ttl=255 time=4.6 ms
64 bytes from 192.168.2.11: icmp_seq=1 ttl=255 time=4.4 ms
64 bytes from 192.168.2.11: icmp_seq=2 ttl=255 time=4.4 ms
^C
--- 192.168.2.11 ping statistics ---
3 packets transmitted, 3 packets received, 0% packet loss
round-trip min/avg/max = 4.4/4.4/4.6 ms

 

=====================

HUB TO SPOKE PING

====================

# execute ping 192.168.3.25
PING 192.168.3.25 (192.168.3.25): 56 data bytes
^C
--- 192.168.3.25 ping statistics ---
131 packets transmitted, 0 packets received, 100% packet loss

 ==================================

 

 

10 REPLIES 10
Toshi_Esumi

Then again, the problem seems to be on the spoke side.

Toshi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors