Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HS08
Contributor

VPN Site to Site

I build site to site vpn connection from fortigate in HQ and sophos xg in branch.

In the tunnel interface in fortigate listen on port8 with ip address xx.xx.xx.230

Screenshot 2025-09-16 071332.png

The vpn connection is established, the branch and hq can communicate but if i traceroute from branch to hq i feel strange why the traffic passing thru another ip in fortigate xx.xx.xx.246 and not to xx.xx.xx.230?

Here my tracert result

Tracing route to 10.7.208.52 over a maximum of 30 hops

1 <1 ms <1 ms <1 ms 10.108.150.1
2 22 ms 16 ms 20 ms xx.xx.xx.246
3 29 ms 20 ms 20 ms 10.7.101.2
4 21 ms 23 ms 18 ms 10.7.208.52

1 Solution
princes
Staff
Staff

Hello HS08,

 

It might be the interface index selected instead of tunnel interface.

Kindly check the below for reference:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-tracert-traceroute-behavior-over-IPsec-VPN...

 

Regards,

Prince

Best regards, Prince singh Fortinet EMEA TAC Engineer

View solution in original post

4 REPLIES 4
Stephen_G
Moderator
Moderator

Hello HS08,

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Thanks,

Stephen - Fortinet Community Team
princes
Staff
Staff

Hello HS08,

 

It might be the interface index selected instead of tunnel interface.

Kindly check the below for reference:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-tracert-traceroute-behavior-over-IPsec-VPN...

 

Regards,

Prince

Best regards, Prince singh Fortinet EMEA TAC Engineer
HS08

make sense, when i assign ip address to the tunnel interface now the tracert showing right path.

Toshi_Esumi

Traceroute's host IPs in the output is just host IPs. Not necessarily ingress or egress interface IPs. They're just to "identify" the hosts.

Toshi 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors