- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN Tunnel Between FortiGate 60C and Cisco 881 Router
Hi Guys,
I desparetly need your help, I'm trying to create a VPN Connection between the Fortigate 60C and Cisco 881 Router. I have tried everything and there is still no positive result. [>:]
Phase 1 negotiation is successfull but there is no Phase 2 Start. I have tried both Links under
http://blog.webernetz.net/2015/02/05/ipsec-site-to-site-vpn-fortigate-cisco-asa/
http://blog.webernetz.net/2015/02/02/ipsec-site-to-site-vpn-fortigate-cisco-router/
And non of them really gets me going forward. Do you have Experience with such devices? I have managed the FortiGate until now without any Problems, have created a VPN but from Forti to Forti. But now we need a VPN for a Customer and this is quite Challaging now...
Thanks for your Help in advance.
Best Regards,
Ziga
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ziga.mlinaric wrote:Hi Guys,
I desparetly need your help, I'm trying to create a VPN Connection between the Fortigate 60C and Cisco 881 Router. I have tried everything and there is still no positive result. [>:]
Phase 1 negotiation is successfull but there is no Phase 2 Start. I have tried both Links under
http://blog.webernetz.net/2015/02/05/ipsec-site-to-site-vpn-fortigate-cisco-asa/
http://blog.webernetz.net/2015/02/02/ipsec-site-to-site-vpn-fortigate-cisco-router/
And non of them really gets me going forward. Do you have Experience with such devices? I have managed the FortiGate until now without any Problems, have created a VPN but from Forti to Forti. But now we need a VPN for a Customer and this is quite Challaging now...
Thanks for your Help in advance.
Best Regards,
Ziga
At seconds link there is no policy configured. insert "vpn to lan", and "lan to vpn".
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ziga.mlinaric wrote:Hi Guys,
I desparetly need your help, I'm trying to create a VPN Connection between the Fortigate 60C and Cisco 881 Router. I have tried everything and there is still no positive result. [>:]
Phase 1 negotiation is successfull but there is no Phase 2 Start. I have tried both Links under
http://blog.webernetz.net/2015/02/05/ipsec-site-to-site-vpn-fortigate-cisco-asa/
http://blog.webernetz.net/2015/02/02/ipsec-site-to-site-vpn-fortigate-cisco-router/
And non of them really gets me going forward. Do you have Experience with such devices? I have managed the FortiGate until now without any Problems, have created a VPN but from Forti to Forti. But now we need a VPN for a Customer and this is quite Challaging now...
Thanks for your Help in advance.
Best Regards,
Ziga
Hello, and welcome to the forum.
Im running several FGT <-> Cisco tunnels, what build are the FGT running?
Fortigate <3
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
FGT is running following Config:
Phase 1 in Image
The connection doesn't even come to the Phase 2...
Are there any special setting that hase to be made on Cisco?
Thanks for your help in advance.
Best Regards,
Ziga
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I hope you can see the Images now. Because I can add only one. :\
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ziga.mlinaric wrote:I hope you can see the Images now. Because I can add only one. :\
can you login trough ssh and show it via CLI
show vpn ipsec phase1-interface <name>
show vpn ipsec phase2-interface <name>
and related snip from
show router static
show firewall policy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry, i can't see the image.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have already solved the problem. It was on the Cisco site that was blocking it.
Tnx for your help. Anyway...
