Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rolo
New Contributor

IPsec Between Fortinet and Mikrotik

Hello, I don't have much experience with this stuff and have a little problem if anyone can help me would be great. i have FortiGate 40F on one side and Mikrotik 2011 on another side. i managed to build IPsec between those 2 and IP sec is UP.

But there is problem i can't have ping or any kind of connection between those 2 networks. On mikrotik i have 192.168.1.0/24 network and on fortinet side i got 192.168.60.0/24 network on Lan ports. If anyone can help me to tell me what should i check to find the problem i haven't much experience with fortigate.

[link]https://ibb.co/0rnHQxN[/link] [link]https://ibb.co/JHwWsW8[/link] [link]https://ibb.co/kHKH6Lp[/link] [link]https://ibb.co/XLPxgD9[/link] [link]https://ibb.co/ysgG7Dy[/link] [link]https://ibb.co/L8vtmf7[/link] [link]https://ibb.co/q59nccM[/link]

11 REPLIES 11
emnoc
Esteemed Contributor III

You need to double check phase2 but 1st have you ran any "diag debug application ike -1" on the fortigate? If you see NO packets back from the mikrotik, than investigate why. You can "diag sniffer packet any "host x.x.x.x" where x.x.x.x is the remote-gw address of the mikrotik.

 

Also I would disable replay detection and your config looks good fwiw. I would not use des or dhgp2 but that is my preference.

 

You problem is most likely  psk mismatch  or the remote-gw are timing out just look at this from a 100k foot view.

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
rolo
New Contributor

I've managed to make it work with GRE tunnel. Ipsec just doesn't work we couldn't find it out why.

Labels
Top Kudoed Authors