Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jvignacio
New Contributor

IPSec tunnel Incoming data problem

hey guys, I recently setup a IPSec tunnel between two offices. They both say they are up but theres only outgoing data on both firewalls, no incoming data which means I cant do things like ping and browse/connect to each office, even though the IPSec tunnel is UP. On each firewall, I created a static route for the other subnet to go out of the IPSec tunnel and I created policies so it allows internal to go out IPSec and IPSec to go to internal. Not sure what I' m missing... can anyone help me please? they are both fortigate 60c. thanks!
5 REPLIES 5
FortiRack_Eric
New Contributor III

You don' t setup policy routes for this, just static routes.

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
jvignacio

Sorry I meant static route. Do you know what could be the problem?
FortiRack_Eric
New Contributor III

I assume you' ve checked your active routing table..?

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
emnoc
Esteemed Contributor III

diag debug flow is your friend. But if you have routes and the fwpolicies, than you missed something simple. Are you using 0.0.0.0/0 in your selectors or have something else? Also is NAT enabled? Do you have any other fwpolicies that might be taking effect ( diag debug flow )

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
jvignacio

My mistake guys, I have a policy set for outgoing data through each WAN port to work during 9-5 weekdats :\ Thanks for all the suggestions though. Cheers.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors