Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TJNIHAL
New Contributor

Site-to-site IPsec VPN with two FortiGates

Hi, I have 2 Fortinet device 60E and 60D. I have been trying to create a VPN tunnel between the device.

 

I followed this cookbook article https://cookbook.fortinet.com/site-site-ipsec-vpn-two-fortigates-56/ and both my devices are behind the NAT So, I had to change the NAT setting beside I followed every single step mentioned in this article. 

In the end tunnel is NOT UP so, I tried to converted the tunnel to custom and disabled NAT-T, then tunnel is UP but traffic is not passing.

Not sure where to look for issue. Any guidance highly appreciate. Both devices have v5.6.2 build1486 (GA) firmware.   Thanks.

1 Solution
sangomab
New Contributor II

Hi there,

try this,

 

 

diagnose debug disable diagnose debug reset diagnose vpn ike gateway clear diagnose vpn ike log filter name YOUR_VPN_NAME diagnose debug application ike -1 diagnose debug enable

 

 

and send back the logs

 

di de di to disable diagnose

sangomab is ... 

View solution in original post

sangomab is ...
4 REPLIES 4
TJNIHAL
New Contributor

Sorry I have posted in the wrong form. I have created a new post in VPN.. Not sure how to delete this post.

TJNIHAL
New Contributor

Sorry, I created the post in wrong form. I have created new Post in VPN form. Use this link https://forum.fortinet.co...m=172678&tree=true PS: No option to delete this post.

amseamans
New Contributor

Are there any errors in the logs for the tunnel?  Phase 1 and Phase 2 are good?  Set up routes and policies to allow traffic? 

sangomab
New Contributor II

Hi there,

try this,

 

 

diagnose debug disable diagnose debug reset diagnose vpn ike gateway clear diagnose vpn ike log filter name YOUR_VPN_NAME diagnose debug application ike -1 diagnose debug enable

 

 

and send back the logs

 

di de di to disable diagnose

sangomab is ... 

sangomab is ...
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors