Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jai_Kishore
New Contributor

VPN traffic dropped

Hi all, My setup is like this :One cisco ISR router 3800 which is connected to internet,after that fortigate 620B with cluster mode,and then 6500 Series cisco MLS switchs in cluster mode with FWSM again in cluster mode We have multiple VPNs on cisco router and as well as on Fortigate firewall.we have multiple branches connected with Easy VPN which is terminated on Cisco router.I have bypass the VPN traffci both Fortigate and cisco Fwsms for VOIP purpus.So we are facing serious issue with virus so I am trying to pass the entire VPN traffic through Fortigate firewall.I have configured separate physical interfaces and configured a policies and route to direct the traffic through firewall in cisco router,switch and fortigate firewalls also. I am able to ping the Fortigate interface IP address from both sides But my problem is when Ian trying to ping the internal IP address the somewhere it is getting dropped where as in firewall logs it is showing only interface IP addresses not the original Src and Dst IP address. Any advices plz. Regards, Jai Kishore
6 REPLIES 6
emnoc
Esteemed Contributor III

I' m confused on what your doing at the firewall policy that you present looks like it has nothing todo with VPN. Qs; Do you have a packet flow topology of what your trying to build? Did you do any diag sniffer captures ? Is this traffic drop b4 the vpn? Is the problem After the VPN ? How are you determining that traffic is actually drop ( counters, diag debug flow, interface counts ,etc.......) What do you mean 6500 in a cluster ( VSS maybe ) ? Are the cisco FWSM performing VPN terminates ( not even sure if cisco ever got ipsec in those ) and or how are they operating as ( L3 routed or transparent ) and how just do they fit into all of this? Can they ( FWSM ) be bypass ? And are we to assume the fortigate are routed ? or transparent ? So many question b4 one could attempt to give you a solid answer. But I would do is to ensure the internet connectivity and then work towards your interior 1st. Perform some spot packet-capture ( all of the device you have mention probably has the function down to the 6500 ) Perform some diag debug flow statistics Conduct traceroutes etc..

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Jai_Kishore
New Contributor

Hi eminoc, Thanks for reply.Here I have depicted the sample picture. the traffic is seems to be dropped after the VPN. The router is performing the VPN Well I have configured two interfaces with 192.168.55.1/24 series at router end and 192.168.95.1/24 at switch end. the VPN traffic is bypassing both fortigate and FWSM firewalls. Fortigate is route mode only well when I tried to take the packet capture it shown no traffic is passing through fortigate firewall.but when I tried to ping from 192.168.95.1 to 192.168.55.1 then firewall is allwoing and able to ping where as if I ping from an different IP address then request timed out.
Jai_Kishore
New Contributor

Hi emicnoc, I have attached the network diagram after passing through the Fortigate. regards, Jai Kishore
emnoc
Esteemed Contributor III

Okay much better, Clarify is this VPN traffic terminated on the FWSM? or this traffic is before the encryptio/decryption on the edge-router? Can you grab a pcap on the fortigate? Are you 100% sure nothing downwind is sNAT or blocking the traffic ( pcap dump and diag debug flow will confirm this ) Ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Jai_Kishore
New Contributor

Hi emnoc, Really very good peace of information u gave me.I have enabled the wireshark.and it gave me good information but some sort I am not able to figure out the issue can you help me,If so can you give me your mail or any thing that is not publicly visible so I can send the PCAP O/P file becoz there is lot of private information of my network is availble.And VPN traffic is terminated on Router itself, No sNAT is enabled on these interfaces. Regards, Jai Kishore
emnoc
Esteemed Contributor III

If so can you give me your mail or any thing that is not publicly visible
But then if I do that it would be pubic visible Do a search for socpuppets blogspot and you can find a few address that I monitor.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors