Dear Members,
i am getting issue with my IPsec tunnel, it show both arrows upward and downward at a time. required help to troubleshoot the issue.
You must have two network selectors. One is up and another is down. If you don't matching traffic to the second selector, it might now come up. Try generating traffic from the local subnet to the other side matching the selector.
Toshi
No Traffic is passed through this VPN
Created on 10-21-2024 09:32 AM Edited on 10-21-2024 09:34 AM
If you run like a continuous pinging, but never get the second phase2 come up, likely the other side of the selector config is not matching the local config.
If you're confident both are matching, you need to run IKE debug hopefully on both sides. Since it's only one IPsec on the local side, you don't have to filter other traffic out but can simply run below:
diag debug reset
diag debug app ike -1
diag debug console timestamp ena
diag debug ena (if not via console)
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.