Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
graham_morrison
New Contributor

IPSec to IPSec Tunnel Traffic

Hi there everyone,

 

With everyone going remote working we have come across an issue.  We have our tech support tunnel that us IT support folk are using.  We have another ipsec tunnel that our users are coming in over.  We cannot get traffic to flow between these tunnels.  So far in setting this up I have:

 

Added the subnets to both tunnels and checked they appear on the client routing tables

Created policy rules with sources and destinations as being the tunnel interfaces

Had sniffers running at the command line and see the traffic going one way over the tunnel and hitting a client pc but nothing coming back.

 

Running wireshark on clients on either side if the tunnel i can see the ping packets hitting them but them not sending anything back.

Am i missing something super obvious? 

6 REPLIES 6
sw2090
Honored Contributor

recheck client routing table. Do you have overlapping subnets there?

recheck client firewall if that is blocking you?


-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

graham_morrison

Thanks for reply.  The tracert from the ipsec clients shows the forst hop as the external ip of the FW so that would suggest to me the route is ok since its trying to route it over the tunnel.  All the clients have their local FW's off as well.

Yurisk

Strange to hear that from PC ping enters the tunnel, but on the FGT sniffer you see nothing, it is highly unikely for ping to enter the tunnel directed to the FGT and never make to the FGT itself. I'd even say it is impossible. 

Have you run "diag deb flow" on those PC's pings ? Make sure no NAT is involved not to miss packets in sniffer.

 

Yuri
https://yurisk.info/ blog: All things Fortinet, no ads.


All opinions are mine only.
graham_morrison

Hi there,

 

I'm sorry i cant have been clear.  I do see the ping on the FGT sniffer when i test this.  I see the echo request but no reply.  It look like traffic can go one way but not the other for each tunnel.

fortihaza
New Contributor

hey man did you manage to achive that cause i am in quite similar problem, i want to route my ipsec remote access vpn to site to site vpn. 

fortihaza
New Contributor

hey man did you manage to achive that cause i am in quite similar problem, i want to route my ipsec remote access vpn to site to site vpn