I have what I believe to be a straight forward interface mode IPsec tunnel setup between two fortigates running 4.0 MR3 patch 18. The settings have been confirmed to be matching on each side and the remote IP's are correct. The static routes are added and are correct and the firewall policies are added on either side and are correct. The tunnel comes up but it does not pass traffic. When I run the following debug trace command I get the below messages when attempting to ping across the VPN tunnel. I don't understand why it is trying to route to the public IP of the remote firewall when trying to traverse the VPN tunnel and I don't know how a route could not exist since the Tunnel to that same Public IP is clearly up
_FW # diagnose debug enable
_FW # diagnose debug flow show console enable show trace messages on console
_FW # diagnose debug flow filter add 192.168.34.1
_FW # diagnose debug flow trace start 100
id=36871 trace_id=30 msg="vd-root received a packet(proto=1, 192.168.0.1:7680->192.168.34.1:8) from local." id=36871 trace_id=30 msg="Find an existing session, id-01b58c79, original direction" id=36871 trace_id=30 msg="enter IPsec interface-vpnmap_21" id=36871 trace_id=30 msg="no route to <Public IP of Remote Firewall>, drop"
Thank you for your help, I am stumped on this issue.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Had the exact same issue today with 4.0 build 665 MR3 Patch 14.
After upgrade to >= 5.0 the problem was gone.
How were the tunnels built? By hand or using a wizard? Just a curiosity question.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
They were handcrafted with love. :)
They worked before, just made following changes:
- underlying interface from WAN2 to WAN1 (PPPoE)
- IKEv1 to IKEv2
- disabled NAT traversal
After the firmware upgrade and no config changes, tunnels were able to pass traffic.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.