Hi,
I have 2 fotrigate UTMs. One of then is 300c V.5.2 other is 50B v4.0. I have a different problem for making ipSec VPn. http://docs.fortinet.com/uploaded/files/1692/creating-a-VPN-with-overlapping-subnets.pdf this document can't work for network.
On site 1 (300c) public ip is 212.156.33.X, local ip is 10.121.0.0/20 (255.255.240.0), 10.212.0.1 ip local interface is 300 C fortigate
On site 2 (50B) public IP is 212.175.55.X, local ip is 10.212.6.0/20 (255.255.240.0), 10.212.6.1 ip local interface is 50 B fotigate
I have read document the above documents link and apply both fortigates. IPsec VPN bridge is UP but there are no any ping or other tarffic site 1 and site 2.
Please help me.
(PS: Sorry for my english.)
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Did you create policies allowing traffic in/out on both sides?
Did you set routes on both sides?
If you have checked the configuration for errors, I would test following:
1) perform a traceroute between the 2 locations. If it works the issue is solved :) , if not proceed with 2
2) run a diag sniffer on your vpn interface (diag sniffer packets <vpn interface> <filter eg ICMP> <loglevel eg 6> 300. check if traffic passes over the vpn
3) check if the traffic matches correct policies and route entries:
diag debug flow filter ...
diag debug flow show console enable
diag debug ena
diag debug flow trace start 100
it should indicate if traffic is taking the correct path and if it matches a security policy.
Johan Witters
Network & Security Engineer
FCNSP V4/V5
BKM NV
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.