Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
New Contributor

Site to site Tunnel not allowing traffic to destination IP

Let me start off by stating that I have very little experience with Fortigate and was pushed onto this project to "fix" this. I have a vpn setup between two sites. Site A is making requests to Site B to an API on a specific (Nat'd) IP, but for some reason I cannot get traffic to that IP. I can see data coming (in the fortigate) in but nothing is making it to the specified server.


Below is the configuration as best as I can describe it. I am sure there is something I am missing. Site A: is not under my configuration but has been assured to be configured "properly" with no Nat'd addresses. Site B: Configuration as follows... Please let me know if you need more info. Static IPSec Tunnel:

  • Wan interface with External (internet facing) IP address of Site A
  • Nat Traversal is enabled
  • Authentication is matched between the sites in Phase 1
  • Phase 2: Several selectors set  Local to remote[ul]
  •  Site B (Nat'd) to Site A (prod)
  •  Site B (Nat'd) to Site A (test)
  •  Site B (Lan) to Site A (prod)
  •  Site B (Lan) IP to Site A (test)[/ul][/ul]

    IPv4 Virtual IP created for the server

  •  (the Site B server) --> (Interface) IpSec Tunnel (Ref) 0[/ul]

    IPv4 policy (Note: that both of these show a caution alert that "all source interfaces are down" but IPsec tunnel shows as Status: Up)

  • Lan - IPSec tunnel (1-1): (Source) (Destination) Site A Server addresses pool
  • IPSec tunnel - Lan  (3-3): (Source) Site A Server addresses pool (Destination)[/ul]

    Static Routes

  • (Destination) (Interface) IPsec Tunnel (Administrative distance) 10
  • (Destination) (Interface) IPsec Tunnel (Administrative distance) 10
  • (Destination) (Interface) Blackhole (Administrative distance) 200
  • (Destination) (Interface) Blackhole (Administrative distance) 200[/ul]

    I used the Forti Cookbook ( to configure this originally.   Unfortunately I am at a loss as to what to try next. Any help would be appreciated.

  • 1 REPLY 1
    Contributor II

    The configuration is correct.

    The Phase 2 is up when you test the traffic?

    From ip can you ping or


    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Top Kudoed Authors