Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ClaudiuGheorghe90
New Contributor

Issues: Lan to Lan Policy and VPN connection after upgrade from 7.0.13 to 7.0.14 Mature

Hello,

The LAN-to-LAN policies do not apply, and there is no traffic on that policy. However, with the VPN, you can connect via FortiClient, but there is no traffic, and you cannot access anything from the local network. None of the LAN IPs respond to PING, and occasionally, it disconnects from the VPN client. All of these issues have been occurring since the firmware update from version 7.0.13 to 7.0.14.

 

Somebody familiar with this issues?

5 REPLIES 5
hbac
Staff
Staff

Hi @ClaudiuGheorghe90,

 

When connected to the VPN, are you able to see routes to internal network? You can run 'route print' command to check.

 

If you can see the routes, please run debug flow on the FortiGate to see what's wrong. Please refer to https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...

 

Regards, 

AEK
SuperUser
SuperUser

Do you mean all lan to lan policies are not passing traffic anymore?

Do you see the legitimate traffic is being blocked in traffic log?

When you say lan IPs are not pingable do you mean FG interfaces?

AEK
AEK
Tec_Informatic
New Contributor

Hello,
It has also happened to us. From 7.0.13 to 7.0.14 the lan to lan policies do not work and do not generate traffic either. If we download 7.0.13 everything is ok.
Do we have any help?
spoojary
Staff
Staff

Run the debugs to see whether the traffic is passing from the FGT or not.

 

di deb res
diagnose debug flow filter clear
diagnose debug flow filter saddr x.x.x.x
di deb flow filter daddr x.x.x.x
diagnose debug flow show function-name enable
di deb flow show iprope en
diagnose debug console timestamp enable
diagnose debug flow trace start 999
diagnose debug enable

 

Siddhanth Poojary
ClaudiuGheorghe90
New Contributor

Lan to Lan I just solved it with this: 

 

config system global
set allow-traffic-redirect disable
end

 

VPN problem: the issue was just for the clients where the vpn client had the range of IP's from the same LAN subnet, , after I changed the subnet class for vpn clients..problem solved. 

 

I hope in the next firmware update this issues will be solved. 

 

Thanks for your help! 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors