Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TheDude
New Contributor II

Site to Site VPN status down

This is not my strongest area but it is the its the task at hand..

Main office 100D v5.2.2

Branch 60D v5.2.2

Followed instructions from video to create a site to site. Went to VPN/Monitor/IPSec Monitor and it shows the status as down. Any guidance would be greatly appreciated. 

1 Solution
TheDude
New Contributor II

https://www.youtube.com/watch?v=sZC0AldHi34

 

I have been going through them line by line and look identical. After completing the wizard, the phase 2 selectors were all zeros. I've manually set them to the correct addresses and it made no difference.

View solution in original post

8 REPLIES 8
rwpatterson
Valued Contributor III

Have you created the policies as well? Without them the tunnel will never come up.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
TheDude
New Contributor II

It built them automatically. 

 

gschmitt
Valued Contributor

TheDude wrote:

It built them automatically.

Did you use the "FGT to FGT" template? That should create nearly everything automatically, so I would assume a Quick Mode mismatch 

AtiT
Valued Contributor

Hi,

Did you set the routing to the VPN interface?

AtiT

AtiT
TheDude
New Contributor II

I did use the FGT-FGT template. Ran the commands suggested by ede_pfau and see that its trying to use my modems provided subnet which does not match what the fortigate gives out. Assuming I need to bridge the modem.

ede_pfau

From "video"...there are hundreds I guess. Link? So that we can check what you've configured yet.

 

In my experience it's almost always the last 1% of the config which doesn't match - PSK, ph1 settings, ph2 settings, Quick mode selectors. Once you have it 100 % identical on both sides it snaps OK.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
TheDude
New Contributor II

https://www.youtube.com/watch?v=sZC0AldHi34

 

I have been going through them line by line and look identical. After completing the wizard, the phase 2 selectors were all zeros. I've manually set them to the correct addresses and it made no difference.

ede_pfau

In Dashboard > Console, please enter the following and post the (text) output from both FGTs here:

diag deb ena

diag deb app ike -1 Stop output by hitting Ctrl-C. This will debug the initial part of the VPN buildup (namely phase1). Hopefully you don't have a lot of VPNs on these FGTs...


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors