Sirs
I'm starting with the fotigate and I am unable to configure the FortiGate to allow PPTP VPN connection from my internal network out to an external server. I setup a policy allowing traffic of the LAN interface, for the LAN IPs and WAN Interface, IP VPN; Service PPTP and GRE;
Enable NAT
(examples) IP WAN: 182.231.220.6 IP LAN: client 10.10.100.124 IP VPN SERVER 201.165.162.190 port1: LAN
Wan1: wan
When I test the connection I have the following in the debug LOG flow : titulo_fw1 # 2015-08-18 15:34:42 2015-08-18 15:34:42 id=13 trace_id=1971 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=6, 10.10.100.124:65401->201.165.162.190:1723) from port1." 2015-08-18 15:34:42 id=13 trace_id=1971 func=init_ip_session_common line=4424 msg="allocate a new session-2e82d9d1" 2015-08-18 15:34:42 id=13 trace_id=1971 func=vf_ip4_route_input line=1603 msg="find a route: gw-182.231.220.1 via wan1" 2015-08-18 15:34:43 id=13 trace_id=1971 func=__iprope_tree_check line=534 msg="use addr/intf hash, len=13" 2015-08-18 15:34:43 id=13 trace_id=1972 func=__ip_session_run_tuple line=2519 msg="DNAT 182.231.220.6:65401->10.10.100.124:65401" 2015-08-18 15:34:43 id=13 trace_id=1972 func=vf_ip4_route_input line=1603 msg="find a route: gw-10.10.255.2 via port1" id=13 trace_id=1971 func=fw_forward_handler line=660 msg="Allowed by Policy-199: SNAT" 2015-08-18 15:34:43 2015-08-18 15:34:43 id=13 trace_id=1972 func=ids_receive line=237 msg="send to ips" id=13 trace_id=1971 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 id=13 trace_id=1973 func=__ip_session_run_tuple line=2505 msg="SNAT 10.10.100.124->182.231.220.6:65401" 2015-08-18 15:34:43 2015-08-18 15:34:43 id=13 trace_id=1973 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, original direction" id=13 trace_id=1974 func=__ip_session_run_tuple line=2505 msg="SNAT 10.10.100.124->182.231.220.6:65401" 2015-08-18 15:34:43 id=13 trace_id=1973 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 id=13 trace_id=1974 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=6, 10.10.100.124:65401->201.165.162.190:1723) from port1." 2015-08-18 15:34:43 id=13 trace_id=1975 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, reply direction" 2015-08-18 15:34:43 id=13 trace_id=1974 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, original direction" 2015-08-18 15:34:43 id=13 trace_id=1975 func=__ip_session_run_tuple line=2519 msg="DNAT 182.231.220.6:65401->10.10.100.124:65401" 2015-08-18 15:34:43 id=13 trace_id=1974 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 id=13 trace_id=1975 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 id=13 trace_id=1978 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=6, 10.10.100.124:65401->201.165.162.190:1723) from port1." 2015-08-18 15:34:43 id=13 trace_id=1976 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=6, 10.10.100.124:65401->201.165.162.190:1723) from port1." 2015-08-18 15:34:43 id=13 trace_id=1976 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, original direction" 2015-08-18 15:34:43 2015-08-18 15:34:43 id=13 trace_id=1978 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, original direction" id=13 trace_id=1976 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 2015-08-18 15:34:43 id=13 trace_id=1976 func=__ip_session_run_tuple line=2505 msg="SNAT 10.10.100.124->182.231.220.6:65401" 2015-08-18 15:34:43 id=13 trace_id=1977 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=6, 201.165.162.190:1723->182.231.220.6:65401) from wan1." 2015-08-18 15:34:43 id=13 trace_id=1977 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, reply direction" 2015-08-18 15:34:43 id=13 trace_id=1977 func=__ip_session_run_tuple line=2519 msg="DNAT 182.231.220.6:65401->10.10.100.124:65401" 2015-08-18 15:34:43 id=13 trace_id=1977 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 id=13 trace_id=1978 func=__ip_session_run_tuple line=2505 msg="SNAT 10.10.100.124->182.231.220.6:65401" 2015-08-18 15:34:43 id=13 trace_id=1979 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=6, 10.10.100.124:65401->201.165.162.190:1723) from port1." 2015-08-18 15:34:43 id=13 trace_id=1979 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, original direction" 2015-08-18 15:34:43 id=13 trace_id=1980 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=47, 10.10.100.124:0->201.165.162.190:2527) from port1." 2015-08-18 15:34:43 id=13 trace_id=1979 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 2015-08-18 15:34:43 id=13 trace_id=1980 func=init_ip_session_common line=4424 msg="allocate a new session-2e82da04" id=13 trace_id=1979 func=__ip_session_run_tuple line=2505 msg="SNAT 10.10.100.124->182.231.220.6:65401" 2015-08-18 15:34:43 id=13 trace_id=1980 func=__ip_session_run_tuple line=2505 msg="SNAT 10.10.100.124->182.231.220.6:0" id=13 trace_id=1980 func=vf_ip4_route_input line=1603 msg="find a route: gw-182.231.220.1 via wan1" 2015-08-18 15:34:43 id=13 trace_id=1981 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=47, 201.165.162.190:0->182.231.220.6:41210) from wan1." 2015-08-18 15:34:43 id=13 trace_id=1980 func=__iprope_tree_check line=534 msg="use addr/intf hash, len=13" 2015-08-18 15:34:43 id=13 trace_id=1980 func=get_new_addr line=2398 msg="find SNAT: IP-182.231.220.6, port-0" 2015-08-18 15:34:43 id=13 trace_id=1980 func=fw_forward_handler line=660 msg="Allowed by Policy-199: SNAT" 2015-08-18 15:34:43 2015-08-18 15:34:43 id=13 trace_id=1980 func=ids_receive line=237 msg="send to ips" id=13 trace_id=1981 func=init_ip_session_common line=4424 msg="allocate a new session-2e82da05" 2015-08-18 15:34:43 id=13 trace_id=1981 func=fw_local_in_handler line=357 msg="iprope_in_check() check failed, drop" Any thing helps (and some tips to understand this log are welcome)
Thanks!
EDIT:
Cause some reason, the all the session helpers was removed.
I Run:
show system session-helper
And get nothing
So I Run:
config system session-helper
edit 1
set name pptp
set port 1723
set protocol 6
next
end
And works! Thanks!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1109 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.