- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPSec tunnel lAN-to-LAN
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Its possible that a VIP is configured on either of the firewalls for the external public IP on which the IPsec tunnel is terminated. Please check and remove the VIP if any.
Regards,
Deepak
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm having the same problem. The error doesn't make much sense since the remote address is a.b.y.z. but the error says the remote address a.b.c.d.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Its possible that a VIP is configured on either of the firewalls for the external public IP on which the IPsec tunnel is terminated. Please check and remove the VIP if any.
Regards,
Deepak
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
omg your right, an old VIP that I wasn't using was somehow being used for that VPN.
thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
i am facing an issue in site to site ipsec vpn, tunnel is up , and i can access remote LAN. but remote lan can not access me, although the policies which i made for remote lan, in that policy i allowed access for remote lan, but still other party is unable to access my lan, can any body guide me what can be the issue.
thank you in advance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The diag debug flow is your 1st command and step in diagnostics. I would execute it and review the output. I would suspect the fwpolicy-id ordering or lack or incorrect route
PCNSE
NSE
StrongSwan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I meet the error as well , there is a Cisco router 2911 build site to site VPN to fortigate 500D . It's not work and I enable debug on fortigate , I found the error "remote address 218.207.163.181 does not match configuration address 112.5.54.2, drop" . there is nothing VIP config about 218.207.163.181 . IP 112.5.54.2 is router's public IP.
BR
Kenneth
