Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NETWORK_USER
New Contributor

ipsec site-to-site vpn traffic not reaching destination

Hello, I have configured a site-to-site vpn between two fortigate 300c FW and I see the tunnel come up but when I try to reach from a host (behind the firewall) from one end of the tunnel to another host at the other end of the tunnel, it does not work. I did packet captures and what I see is that if lets say if I start a ping from host1 behind fw 1 to a host2 behind fw2 then I see the icmp echo packets reaching fw2 (virtual vpn interface) but FW2 does not send it out the interface where host2 is connected. Same thing happens the other way round too. Am I missing any configuration? I would assume firewall knows the hosts that are directly connected to their interfaces and should know how to route traffic to them. But I am totally confused why this is not working. Anybody has any suggestions? Thank you.
12 REPLIES 12
Mr_President

taheireem wrote:

[attachImg]https://forum.fortinet.com/download.axd?file=0;123076&where=message&f=04-27-15 10.21 . 08 AM.jpg[/attachImg]

 

Even I have faced the same issue but figured it out as it was related to upgrading of FortiOS.

 

 

What FortiOS version was causing problems?

 

I also have this issue. VPN is up but only "Outgoing data" is registered in  counters, no "Incoming data".

 

VPN is between Fortigate and Checkpoint.

aspid

Same issue here, v5.0,build4459

I tried with several static route configurations but still no traffic outbound through VPN tunnel.

Mr_President

I solved my problem.

Fortigate VPN configuration was good from the start.

The other side(which is not under my control) had something wrong in the setup.

 

 

Labels
Top Kudoed Authors