Hello, I don't have much experience with this stuff and have a little problem if anyone can help me would be great. i have FortiGate 40F on one side and Mikrotik 2011 on another side. i managed to build IPsec between those 2 and IP sec is UP.
But there is problem i can't have ping or any kind of connection between those 2 networks. On mikrotik i have 192.168.1.0/24 network and on fortinet side i got 192.168.60.0/24 network on Lan ports. If anyone can help me to tell me what should i check to find the problem i haven't much experience with fortigate.
[link]https://ibb.co/0rnHQxN[/link] [link]https://ibb.co/JHwWsW8[/link] [link]https://ibb.co/kHKH6Lp[/link] [link]https://ibb.co/XLPxgD9[/link] [link]https://ibb.co/ysgG7Dy[/link] [link]https://ibb.co/L8vtmf7[/link] [link]https://ibb.co/q59nccM[/link]
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I don't see any particular problem on the 40F config, although I would remove the second static route for 192.168/16. But it shouldn't break anything even if it's there.
I would suspect the other side, but first sniff packets on the FGT while you ping from FGT's local toward the other side. You need to disable asic offloading (set auto-asic-offload diable) on both policies in CLI to see all packets. Don't forget to reenable it after you're done.
Hi, do you have a rule on Mikrotik in NAT that allows communication between subnets? It must be placed in front of a global masquerade or NAT.
/ip firewall nat> add src-address 192.168.1.0/24 dst-address 192.168.60.0/24 action=accept
We operate about 20+ IPsec tunnels between Mikrotik and FGT and it's rock stable.
Jirka
Hi, Thanks for replying me, yes i've created that rule too on mikrotik side i think it should be like that
Hi, Thanks for replying for me i've created that rule too on mikrotik side of course [link]https://ibb.co/WxpJB84[/link]
Hey Jirka,
So I see u have a lot of experience with IPSec between Mikrotik and FGT, i have one setup between my two sites but https traffic just doesn't seem to go through, any idea why that might happen?
Thanks a lot in advance.
Hi thank you so much for replying on me i can provide mikrotik configuration too i have also rule to have 2 subnets connection between https://ibb.co/WxpJB84 . also i will try packet sniffing too i've never done it on fortigate so ill need some time google it :D. any ideas what can be problem on mikrotik side i know its hard to say like this
Did you do a double check IPsec setting on Mikrotik? Mainly DH and PFS group settings, lifetime and NAT Traversal?
I don't think the mistake will be on FortiGate's side.
Jirka
Hi so sorry for a late reply so here is the configuration on both side
Hi,
i'm not here to helping you sorry BUT next time ALWAYS HIDE your ips in every image. It's a must if they are open. Trust me.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1721 | |
1098 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.