Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
galal2010
New Contributor

Site to Site VPN Down

Site to site VPN one site DDNS is Down

Dears

I configured stie to site VPN between 2 Fortigate firewalls and the tunnel is down

I have 2 Fortigate sites

Site 1 : FGT60 use DDNS

i have 3 WAN interfaces (Wan 1 , Wan 2 , Wan 3) connected to internet through ADSL router so they have private IP and router do NAT for real IPs these interfaces are connected to SDWAN zone with IP (0.0.0.0/0.0.0.0)

VPN configuration on this site:

remote gateway: static IP address

IP address: (Public IP of remote site)

interface: WAN 1 (has private IP)

Site 2 : FGT30 has static Public IP

VPN configuration on this site:

remote gateway: Dyanmic DNS

IP address: (FQDN)

interface: WAN interface with Public IP

 

 

10 REPLIES 10
kvimaladevi

Hi galal2010,

 

I hope you have enabled Nat T on both the ends? 

Please get the below logs by bringing up the tunnel to check where exactly the issue is

# diagnose vpn ike log-filter dst-addr4 x.x.x.x --->replace x.x.x.x with the public IP of the remote site
# diagnose debug application ike -1
# diagnose debug enable

Regards,

Vimala

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors