Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
theo102
New Contributor

Starlink SD-wan to fortigate tunnel

Hello,

 

We have a interesting Setup. We have the normal starlink setup + we have a managed router which our provider is using to provide us with a static IP address. They have a ipsec tunnel to our Fortigate and then we have a ipsec site to site vpn back to them. The tunnel itself comes up fine but then nothing can resolve cant go to yahoo.com cnn.com but it has internet access you can ping 8.8.8.8 and access most internal sites. 

 

Has anyone seen this issue before and have any recommendations? 

3 REPLIES 3
kaman
Staff
Staff

Hi theo102,

The fact that you can ping 8.8.8.8 but can't reach yahoo.com indicates that DNS is not resolving domain names properly.


Please review your firewall policy to see which services are allowed, and try pinging google.com to verify connectivity.


Take the debug flow filter logs and share us the output
https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/54688/debugging-the-packet-flow


Regards,
Aman

theo102
New Contributor

This only happens when we plug Starlink in. Our old ISP on this same SD-WAN member does not have this problem. It seems to be something related to us using a static ip carrier with a managed router and Starlink?

sjoshi

Hi,

 

Are you accessing internet via the direct ISP or via the VPN tunnel.

Share below output:-

get router info routing-table all

 

What is the DNS you have setup on the FGT

Network> DNS

share snap

 

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors