as the title implies, anyone could share on how to troubleshoot if the ISP Router blocks/not accepting ipsec vpn protocol?
I setup DialUp VPN wherein remote sites able to established from HO-remote sites, Dial VPN is working already, recently our HO acquired new ISP, if remote sites pointing to the new ISP tunnel is not showing up. Tried to reboot remote site firewall and modem just to clear in cache but no avail, reverting back to old ISP and VPN is tunnel is working fine.
Fortigate Newbie
I would just sniff at both sides of FG and see what one end is sending, which the other end is not receiving. It could be UDP 500 or 4500 blocked depending on NAT-T or not. Or could be just ESP(50)/AH(51) blocked after SAs have been established. Time to time this happens to our new customers when we try setting up IPSec between us and the customers.
User | Count |
---|---|
2624 | |
1390 | |
804 | |
667 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.