Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

ipsec passthrough

How do i know whether ipsec passthrough option is enabled or disabled in my FGT ? My firmware is 2.80 Build 250 ( MR5 )
7 REPLIES 7
Not applicable

Hi Redhatsup, From an earlier post, you can check using the CLI: # get config [...] set firewall passthru ipsec disable set vpn ipsec unknown_spi disable [...] (see http://support.fortinet.com/forum/post.asp?do=reply&messageID=6514&smode=1&tmode=1&p=2&toStyle=m) - Steve
Not applicable

There is no command for : get config in Firmware 2.80 MR5 when i type get config i get the below error Fortigate-60 $ get config command parse error before ' config' Any other options ?
Not applicable

Rats... the link should be: http://support.fortinet.com/forum/m.asp?m=1355&p=2&tmode=1&smode=1&key=&language=
Not applicable

Does anyone have an answer to this question?
UkWizard
New Contributor

Syntax is different in 2.8, so this is incorrect. Also strangely this feature doesnt even exist anymore in the later revisions of firmware. I cannot remember which was the last revision that still had it in (its mentioned somewhere in this forum) think it was 2.8 MR6 ?? However, IPSec should pass through the unit anyway, if it doesnt work for you, its probably the NAT that is breaking it. You need a remote firewall (that you are connecting to) and a VPN client that BOTH support NAT-Traversal. What are you trying to get working ?
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

I would like to set up a VPN site-to-site between 2 fortigates but have 2 other fortigates in between. ie: SubA -> Forti1 -> SubB -> Forti2 -> Internet -> Forit3 -> SubC -> Forti4 -> SubD I can create a VPN between Forti2 & Forti3 no probs but would like to create a VPN between Forti1 & Forti4 so Forti2 & Forti3 have to passthru the IPSEC
UkWizard
New Contributor

As long as NAT Traversal is turned on for the VPN configurations of the firewalls at the ends of the tunnel, should work fine. If it doesnt, its probably a routing issue instead. Otherwise couldnt you just vpn between 2 and 3 instead ?
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors