Hi,
Issue is as above. Peering firewall is a Cisco Firepower.
Site A - FW A (Fortigate) <IPSEC tunnel> FW B (Cisco Firepower) - Site B
IPSEC P1, P2 is up and green. We're attempting SSH to reach Site B machine from Site A. We are seeing the traffic leaving from site A, routed through the tunnel interface via a diagnose sniffer packet, and from the Site B machine tcpdump we are seeing the Syn traffic reaching the machine and return traffic sent. FW B's administrator is seeing the return traffic from Site B as well and forwards it back to Site A, but we're not seeing the traffic on Fortigate (FW A) and causing a timeout of the SSH attempt either from diagnose sniffer packet, network capture from the Fortigate or a diagnose debug flow.
I've been scratching my head and not too sure on what's the next step I could take, so any feedback or questions is appreciated.
Thanks in advance.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
We had the same issue, I worked with Fortinet support and tech support for the other side and we couldn't figure it out either. What we ended up doing was migrating the tunnel off of our secondary ISP to our Primary and it came up.
Hi theengineer
Please run sniffer for both side public IP address and check if you see in and out esp packets on FGT A.
It's possible that ISP on site A FGT which is used to bind this vpn tunnel is blocking incoming esp traffic.
Thanks
Hi the engineer,
Are you able to do ssh if the traffic is being initiated from Site B side? Is the flow of traffic same.
Please take a wireshark capture on FGT by initiating the traffic from Site A.
diag snif packet any 'host <remote_side_public_ip> and esp' 6 0 l
Also take the wireshark capture on both the end.
Please share the output cmd of phase2 selectors:-
diag vpn tunnel list name <Phase1_name>
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1640 | |
1066 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.