Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
juri
New Contributor

VPN is up but traffic no pass

Dear all please could you please help us?

we have got a VPN with an customer.

The VPN come up but it seems that no traffic pass trought the vpn.

 

When the i try to ping  server in VPN proxy id, i can see the packet in ingress, but the customer says that no reply return to him...

 

in a  debug mode i don't know how is possible we receive the message  "no route to 93.62.x.x (ip pub of the customer) , drop"

 

below the trying from a ping:

04 ses.npu_state=0x00000000" id=20085 trace_id=116 func=ipsecdev_hard_start_xmit line=178 msg="enter IPsec interface-CUSTOMER" id=20085 trace_id=116 func=esp_output4 line=688 msg="no route to 93.62.x.x, drop" id=20085 trace_id=117 func=print_pkt_detail line=4918 msg="vd-root received a packet(proto=1, 192.168.107.29:2->172.26.107.107:0) from port1.85. type=0, code=0, id=2, seq=9331." id=20085 trace_id=117 func=resolve_ip_tuple_fast line=4982 msg="Find an existing session, id-007a10d5, reply direction" id=20085 trace_id=117 func=vf_ip_route_input_common line=2583 msg="find a route: flag=04000000 gw-172.26.107.107 via CUSTOMER" id=20085 trace_id=117 func=npu_handle_session44 line=1028 msg="Trying to offloading session from port1.85 to CUSTOMER, skb.npu_flag=00000400 ses.state=00010204 ses.npu_state=0x00000400" id=20085 trace_id=117 func=ipsecdev_hard_start_xmit line=178 msg="enter IPsec interface-CUSTOMER" id=20085 trace_id=117 func=esp_output4 line=688 msg="no route to 93.62.x.x, drop

 

 

any ideas?

4 REPLIES 4
Sidewaysguy
New Contributor III

Hi there,

 

Is the device on the other side of the vpn a Fortigate?  Have you defined inbound and outbound policies for the traffic?  Have you defined the appropriate subnets in Phase 2 or is it configured as 0.0.0.0/0.0.0.0?  If the vpn is up, can you ping anything on the other side or do you receive the same message?

sagipael

i have the same issue.. 

policies and static route have configured.. 

 

anyone found whats wrong?

lookie

Hi Sagipael,

 

I have the same issue...  Did you resolve this issue ?

sagipael

Hi,

 

Yes i did, in my setup, i have point2point to my ISP - with private IP.

and the Public subnets are on different interface.

 

i changed the interface for the ipsec tunnel to be the P2P interface, and set the Local Gateway to the IP from the local interface.

 

http://prntscr.com/oadwzj

 

hope it will fix the issue in your case.

 

Thanks

Sagi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors