Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sindbad
New Contributor

VPN Ipsec is up but can’t ping

I have a fortigate on v6. I have setup ipsec vpn. It’s connected to a sophos xg firewall. The vpn is showing up. I can’t ping. I have on both firewalls the policy enabled for vpn to lan and lan to vpn. I have static route added on fortigate. I see incoming log but outgoing log is 0. I hope someone can help me.
27 REPLIES 27
Ashik_Sheik

Hi,

 

By default you can't ping from fortigate to VPN site LAN.To ping from fortigate you should do source ping ..like eg

 

#exe Ping-option source {your LAN interface IP}

#exe Ping {destination VPN LAN IP}

 

Now you should be able to ping 

 

Regds,

 

Ashik,NSE8

Ashu 

 

Ashu
sindbad

1) I have a windows client on the fortigate side. I would like to ping to a windows system on the sophos client.

This is not possible?

 

2) I have to execute the command through the cli you mean?

Ashik_Sheik

Behind LAN interface systems can ping other side if your conf is fine.But from fortigate you should do source ping which i posted earlier .

 

Regds,

 

Ashik

Ashu 

 

Ashu
Ashik_Sheik

Hi,

 

Get me your LAN interface IP or Conf and also let me know Which IP u want to ping .

 

I can give you exact cmd..

 

Regds,

Ashik

Ashu 

 

Ashu
shafeekshefi

hi ashik,
i have same issue here i have configured vpn with my fortigate to draytek. but tunnel is up and i can ping from dryatek but i can't ping from fortigate.
kindly help.
thank you.

sindbad

Got it.

Unfortanetly I can't ping from the FG clients to the Sophos clients. Sophos clients to FG clients is working fine.

I do have a VPN connection. So I can remote from Sophos clients to the FG clients.

 

What do you need from my end, so you can help me out. Thanks a lot for your help. Almost there!!

sindbad

LAN IP: 192.168.104.0 (sophos)

Want to ping the machine: 192.168.104.22 (machine is ofcourse online).

sindbad

@Ashik helped me through a remote session. Changed a policy and now I can ping from FG LAN to Sophos LAN.

 

All working and thanks to @Ashik!

SirichaiJi

Ashik, Thank i got problem like this. Its done!

How can send log to NAS (Qnap) to other site by vpn ? One thing you have to know I got 2 FG device each HQ and Brand site but only one nas device (192.168.10.26) then HQ is using that and yes log has been recorded to nas. then i want Brand site send log to nas as well by vpn site to site  (192.168.10.26). Please help thank

 

 

New for Foritgate 

My English skill so weak 

Ashik_Sheik

Hi

 

Try pinging from client behind FG , from Fg u can't ping directly .

 

Give me more details on NAS what do u want ti record and from where do u want to record.

 

regds,

 

ashik

Ashu 

 

Ashu
Labels
Top Kudoed Authors