- MBR -
NSE1, NSE2, NSE3
FGT60D/E, FWF60D/E, FGT200D
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Ahead of the Threat. FCNSA v5 / FCNSP v5
Fortigate 1000C / 1000D / 1500D
- MBR -
NSE1, NSE2, NSE3
FGT60D/E, FWF60D/E, FGT200D
I know route based vpn' s are preferred but i some cases i need a policy based vpn.Why do you think you need policy based? Route-based is so much better and easier to diagnosed and I never had a instance where route-based would not work. I mean vpns to openswan, asa,fortigates,checkpoints , halon or juniper. I don' t think I ever had a route-based NOT work. Just something to think about. Back to your dilemma, what does the diagnostic output show when it fails; e.g diag debug flow for starters That might give you some clues as to what happening. Also ensure your fwpolicies ordering is correct. I wasted 2 hours of my time trying to gain access to a vendor remote fortigate, just to find out a policy was trumping his ipsec-policy. We still billed him out for 4 hours. fwiw: policy based vpn are way more harder to t-shoot imho
PCNSE
NSE
StrongSwan
PCNSE
NSE
StrongSwan
- MBR -
NSE1, NSE2, NSE3
FGT60D/E, FWF60D/E, FGT200D
PCNSE
NSE
StrongSwan
- MBR -
NSE1, NSE2, NSE3
FGT60D/E, FWF60D/E, FGT200D
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.