- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Site to Site VPN status down
This is not my strongest area but it is the its the task at hand..
Main office 100D v5.2.2
Branch 60D v5.2.2
Followed instructions from video to create a site to site. Went to VPN/Monitor/IPSec Monitor and it shows the status as down. Any guidance would be greatly appreciated.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
https://www.youtube.com/watch?v=sZC0AldHi34
I have been going through them line by line and look identical. After completing the wizard, the phase 2 selectors were all zeros. I've manually set them to the correct addresses and it made no difference.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you created the policies as well? Without them the tunnel will never come up.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It built them automatically.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
TheDude wrote:Did you use the "FGT to FGT" template? That should create nearly everything automatically, so I would assume a Quick Mode mismatchIt built them automatically.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Did you set the routing to the VPN interface?
AtiT
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did use the FGT-FGT template. Ran the commands suggested by ede_pfau and see that its trying to use my modems provided subnet which does not match what the fortigate gives out. Assuming I need to bridge the modem.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
From "video"...there are hundreds I guess. Link? So that we can check what you've configured yet.
In my experience it's almost always the last 1% of the config which doesn't match - PSK, ph1 settings, ph2 settings, Quick mode selectors. Once you have it 100 % identical on both sides it snaps OK.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
https://www.youtube.com/watch?v=sZC0AldHi34
I have been going through them line by line and look identical. After completing the wizard, the phase 2 selectors were all zeros. I've manually set them to the correct addresses and it made no difference.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In Dashboard > Console, please enter the following and post the (text) output from both FGTs here:
diag deb ena
diag deb app ike -1 Stop output by hitting Ctrl-C. This will debug the initial part of the VPN buildup (namely phase1). Hopefully you don't have a lot of VPNs on these FGTs...
