Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MBR
New Contributor III

Policy Based VPN' s not workinf in FortiOS 5.2

Hi all, Anyone else having problems with policy based VPN firewall policies not working after upgrading to FortiOS 5.2? My firewall policies using the new ' IPSEC" action are completely ignored. When i change the action to Accept or Deny the firewall policy is enumerated and working correctly Changing back to IPSEC and it' s completely ignored again and a firewall policy lower in the chain is hit. Best Regards, MBR

- MBR -

NSE1, NSE2, NSE3

FGT60D/E, FWF60D/E, FGT200D

- MBR - NSE1, NSE2, NSE3 FGT60D/E, FWF60D/E, FGT200D
11 REPLIES 11
emnoc
Esteemed Contributor III

good tidbit of information Was TAC indicating this is a FortiOS5.2 GA quirk only ?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
MBR
New Contributor III

They didn' t investigate the issue any further. They just told me that Fortinet recommends to always use the " Create new" button to create VPN policies ?!?! I don' t have a old FortiOS system available to test if older versions also have this issue. If anyone want to check. Perform these steps 1) Create an ipsec firewall policy using " insert policy above/below" 2) Login to CLI 3) perform these commands configure firewall policy edit [policy ID] get 4) Look for the outbound parameter. Should be enabled to function properly.

- MBR -

NSE1, NSE2, NSE3

FGT60D/E, FWF60D/E, FGT200D

- MBR - NSE1, NSE2, NSE3 FGT60D/E, FWF60D/E, FGT200D
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors