Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
iasupport
New Contributor II

can't establish VPN between two Fortigates

Hi all, I'm having trouble getting 2 fortigate firewalls to connect via VPN, it looks like the phase1 is up but the phase2 never gets triggered. Even if I execute a ping between the two sides it never comes up. I've attached a screenshot of the VPN settings at both ends as well as the static routes and the firewall rules that I've got configured.

 

I've tried running the Fortigate to Fortigate IPSEC wizard and I get the same result. I currently have NAT disabled at both ends but I've tried it with it enabled and enabled/disabled at both ends. I've checked and the preshared keys are the same and they're both using AES256-SHA256 DH14 on both the phase1 and phase2s

 

I'm really confused, can anyone offer any advice?

 

 

mal2nor.pngnor2mal.pngmal2nor-firewallrules.pngmal2nor-staticroute.pngnor2mal-firewallrules.pngnor2mal-staticroute.png

1 Solution
iasupport
New Contributor II

Hi all, ignore this. I've just gone through it again this morning (after hours last night) and realised I was setting both ends up to dial out. Now I've changed it and everything has come up.

It's amazing what some sleep and fresh eyes will do. I'll leave this here in case it helps anyone else.

View solution in original post

1 REPLY 1
iasupport
New Contributor II

Hi all, ignore this. I've just gone through it again this morning (after hours last night) and realised I was setting both ends up to dial out. Now I've changed it and everything has come up.

It's amazing what some sleep and fresh eyes will do. I'll leave this here in case it helps anyone else.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors