Dear all please could you please help us?
we have got a VPN with an customer.
The VPN come up but it seems that no traffic pass trought the vpn.
When the i try to ping server in VPN proxy id, i can see the packet in ingress, but the customer says that no reply return to him...
in a debug mode i don't know how is possible we receive the message "no route to 93.62.x.x (ip pub of the customer) , drop"
below the trying from a ping:
04 ses.npu_state=0x00000000" id=20085 trace_id=116 func=ipsecdev_hard_start_xmit line=178 msg="enter IPsec interface-CUSTOMER" id=20085 trace_id=116 func=esp_output4 line=688 msg="no route to 93.62.x.x, drop" id=20085 trace_id=117 func=print_pkt_detail line=4918 msg="vd-root received a packet(proto=1, 192.168.107.29:2->172.26.107.107:0) from port1.85. type=0, code=0, id=2, seq=9331." id=20085 trace_id=117 func=resolve_ip_tuple_fast line=4982 msg="Find an existing session, id-007a10d5, reply direction" id=20085 trace_id=117 func=vf_ip_route_input_common line=2583 msg="find a route: flag=04000000 gw-172.26.107.107 via CUSTOMER" id=20085 trace_id=117 func=npu_handle_session44 line=1028 msg="Trying to offloading session from port1.85 to CUSTOMER, skb.npu_flag=00000400 ses.state=00010204 ses.npu_state=0x00000400" id=20085 trace_id=117 func=ipsecdev_hard_start_xmit line=178 msg="enter IPsec interface-CUSTOMER" id=20085 trace_id=117 func=esp_output4 line=688 msg="no route to 93.62.x.x, drop
any ideas?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi there,
Is the device on the other side of the vpn a Fortigate? Have you defined inbound and outbound policies for the traffic? Have you defined the appropriate subnets in Phase 2 or is it configured as 0.0.0.0/0.0.0.0? If the vpn is up, can you ping anything on the other side or do you receive the same message?
i have the same issue..
policies and static route have configured..
anyone found whats wrong?
Hi Sagipael,
I have the same issue... Did you resolve this issue ?
Hi,
Yes i did, in my setup, i have point2point to my ISP - with private IP.
and the Public subnets are on different interface.
i changed the interface for the ipsec tunnel to be the P2P interface, and set the Local Gateway to the IP from the local interface.
hope it will fix the issue in your case.
Thanks
Sagi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1661 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.