Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ITAxess
New Contributor

IPSec Tunnel to MicroTik

Hello! One of my IPSec Tunnels connects my Fortigate 300C with a MicroTik Firewall. Tunnel goes up when someone behind the MicroTik generates traffic. Problem: Tunnel stays down if traffic is generated behind my Fortigate! Why I am unable to brind up the Tunnel from my side? my config: Phase 1 set interface " port9" set nattraversal disable set mode aggressive set proposal aes256-sha1 set remote-gw 1.2.3.4 Phase 2 set auto-negotiate enable set keepalive enable set pfs disable set phase1name " name" set proposal aes256-sha1 set replay disable set dst-subnet 192.168.1.0 255.255.255.0 set src-subnet 192.168.2.0 255.255.255.0 Whats the Problem?
3 REPLIES 3
TheJaeene
Contributor

Maybe the Mikrotik FW is only configured to act as a Initiator, not a responder. Regards, Jan
rwpatterson
Valued Contributor III

If the phase 2s aren' t an exact match, that could happen. If the MicroTik has a subset of yours, it' s in the allowed range and will open the tunnel. If your FGT is more broad than what the MT is expecting, it will not allow a connection. My two cents...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
billp
Contributor

A lot could also depend on the firmware version of the Mikrotik. They seem to have a new firmware revision every 1-2 months, frequently with updates to tunneling protocols.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Labels
Top Kudoed Authors