Good day,
Please note that we have successfully replaced the FortiGate Firewall 60E with a FortiGate Firewall 100F using FortiConverter. While most services are functioning correctly, we are currently experiencing issues with VPN connectivity. We cant connect to VPN seems like the SSL-VPN configurations on E60 was never converted to FortiGate Firewall 100F.
Thank you
@ Anthony_E
Hi,
are we talking about SSL VPN or IPsec VPN connections which are not working?
Greetings
It is SSL VPN connection not working
Then, what error are the clients getting? show us under "config vpn ssl settings" first.
Depending on what's in there, we'll ask "portal" config, etc. next.
Toshi
Dear keaolebogapine94,
Could you please specify what kind of VPN is not working?
Did you run any sniffer / ike debug , if not try the following :
1) diagnose sniffer packet any " host x.x.x.x and host y.y.y.y" 4 0 l , where x.x.x.x is the local IP and y.y.y.y is the IP address of remote gateway.
2) IKE debug :
diagnose vpn ike log filter name name_of_affected_IPSec_tunnel
diagnose debug app ike -1
diagnose debug console timestamp enable
diagnose debug enable
3) Debug flow for the traffic which is supposed to be encrypted:
diagnose debug flow filter saddr XXXXXX <----source IP
diagnose debug flow filter daddr YYYYYY <----destination IP
diag debug flow show function-name enable
diag debug flow show iprope enable
diagnose debug console timestamp enable
diagnose debug flow trace start 9999
diagnose debug enable
Once the debug from 3) is ready, please start icmp from XXXXXX towards YYYYYY which is part of remote encryption domain .
Best regards,
Fortinet
Created on 05-29-2025 01:48 AM Edited on 05-29-2025 02:02 AM
Hi @syordanov
We having 60E Firewall in our office which we currently using but the firewall reach end of life we replacing it with 100F FortiGate Firewall we used Forti Converter to migrating firewall configurations but we having issues with Forti Token not being migrated to 100F Firewall. All the policy and configured have been migrated but the Forti Token for VPN are not configured.
Thank you
If it's an IPsec VPN config, the converter didn't have to "convert" it. We regularly copy&paste IPsec VPN config ("config vpn ipsec phase1-interface" and "config vpn ipsec phase2-interface") from one FGT to another type of FGT (same OS version though) to move around the VPN. So the problem is not the IPsec config itself but something else.
Just go through the regular VPN/IKE debug process @syordanov is suggesting.
Toshi
User | Count |
---|---|
2609 | |
1390 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.