- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sovled:FEC not enabled for IPSEC(Update:Not works for dialup mode)
I already followed the official document to set ipsec phase1 and firewall policy,the server side still can't enable.But on the client side,fec enabled and working.System is fortigate 7.4.1 and licensed.
this is debug log:
and this is my config:
But on the other side.the client,FEC is enabled and working.
This is debug log:
and this is my config:
Solved! Go to Solution.
- Labels:
-
FortiClient
-
FortiGate
Nominate a Forum Post for Knowledge Article Creation
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Solved,dial up mode server will generate other one tunnel.Like name_0,name_1,etc.So need use "diagnose vpn tunnel fec name_0",not "diagnose vpn tunnel fec name" to check logs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @YuChow,
Can you provide the output of the following commands:
diagnose vpn tunnel list
show vpn ipsec fec
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
and my net packet loss always about 10%.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have test if use p2p with out NAT in a local test.FEC works.The FEC not works when one side behind NAT?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Local test,using dialup mode.Server(NGF-1) side fec enabled=0,not works.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Solved,dial up mode server will generate other one tunnel.Like name_0,name_1,etc.So need use "diagnose vpn tunnel fec name_0",not "diagnose vpn tunnel fec name" to check logs.