Fortigate 60C
v5.2.7,build718 (GA)
Hi there.
I created a vpn ipsec between my FG60C and a Netgear FVS336G.
The vpn is up and hosts in my subnet can be ping from the remote subnet (behind the Netgear FVS336G).
I can ping hosts of the remote subnet with the Fortigate's CLI, but i can't with the cmd.exe of my PC (behind the FG60C).
All firewalls off.
Did i miss something ?
any help would be great, THX.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
No replies ?
Just tell me if my problem is not clear enough .
I'm assuming you have a proper policy on the FG60C from local subnet to the remote one into the tunnel interface or zone. Then you need to sniff if it's actually going into the tunnel. If not, the next step would be flow debug to see why the FG is dropping the packets.
But you generally wouldn't be able to ping the remote host from the FG unless you specify the source IP on the LAN side. Are you sure the policy doesn't have NAT on? What do you see as the source IP in sniffing when you ping from the FG?
Policy from local to remote subnet is OK.
No NAT on on both policy.
What do you mean by "sniffing if it's actually going into the tunnel" ?
Is there a specific command ?
Thx.
This is the syntax of sniffing:
http://kb.fortinet.com/kb/viewContent.do?externalId=11186
then this is for flow debugging:
http://kb.fortinet.com/kb/documentLink.do?externalID=FD33882
Thank you. i'll try that.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.