Hello team,
I successfully configured phase 1 and phase 2 ipsec vpn having private ip's as peers (WAN).
On one side I have fortigate, on the other side Palo Alto.
Both VPN phases go up but when I try to generate traffic I never get the return responses, either way.
Fortegate side I see correctly routed traffic to the ipsec tunnel but I never see the replies. Palo Alto side is the same, I see traffic is routed correctly but I never see the replies.
The strange thing is that seeing traffic routed correctly to the ipsec tunnel I would expect to see traffic on both sides.
Following screenshot from either sides
Any suggestions for troubleshooting?
It occurred to me to try as a test to modify phase two by specifying 0.0.0.0/0/0 for both remote and local to see if maybe some NAT is present that I am not aware of.
Thanks in advance for the support
BR
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Does Palo support 0.0.0.0/0 phase 2?
As you are seeing traffic enter the ipsec tunnel on both sides, do you see packets being received on both sides as well? Besides phase1 and phase2 selectors being up and configured correctly, please check whether the firewall policy, routing are configured correctly. You can also set NAT-T to force in order to force the tunnel to form over port4500 just in case there are potential NAT devices in the ISP side changing and potentially dropping the packet.
I have the same issue did you find a fix?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.