We have established a VPN connection with a FortiGate firewall in Stockerau.
Steyr -> Stockerau works.
Stockerau -> Steyr unfortunately not, it is not routed into the VPN tunnel although there is a static route with 10.30.0.0/16.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Check the inbound and outbound traffic on the policy
then check static route the Steyr is traffic send via same GW or not
Take debug flow
Hi,
You need to make sure the route which you have created for this particular destination should be active in the routing table.
# get router info routing-table details 10.30.0.0
(Make sure the route should be shown with * sign)
Also make sure there is no policy route created for the same with any other interface.
Also make sure you have outbound policy allowing traffic from your LAN towards the tunnel interface.
If you still see the traffic for this subnet is taking default route instead of tunnel interface route, verify the flow with debug flow.
# diagnose debug flow filter sa <source-IP_lan-PC>
# diagnose debug flow filter da <10.30.0.x>
# diagnose debug flow show function-name enable
# diagnose debug flow trace start 100
# diagnose debug enable
You can also refer the below article for debugs:
Regards,
prince
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.