Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
birillo
New Contributor

issue sending backup to ftp server

Hi,

I'm trying to schedule a full-config backup, from a 40F to a ftp server visible on vpn s2s.

 

using this command:

execute backup full-config ftp '/xxx/FGT_%%date%%.txt' 10.3.64.113 user pwd

 

I receive this output:

"Send config file to ftp server via vdom root failed."

 

ping from fgt to the server not working, so I did a packet capture for destination ip 10.3.64.113 and I found that the Fortigate use, by default, the wan interface, but in this case that port is disabled and I'm using A port as a Wan port.

 

what can i do to route the backup procedure correctly via vpn s2s using the correct tunnel-interface?

11 REPLIES 11
dingjerry_FTNT

Hi @birillo ,

 

You did not assign an IP to "VPN-SF-HQ".

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-IP-address-on-an-IPSec-tunnel-in...

 

If the said IPSec VPN interface has no IP assigned, when traffic originated from FGT itself is being sent to this IPSec VPN tunnel, it will pick up one interface IP on this FGT as the source.

 

So always testing with passthrough traffic which has its own source IP.

Regards,

Jerry
birillo
New Contributor

Hi @dingjerry_FTNT thanks I resolved.

 

- assigned IP to vpn tunnels

- added a static route to destinations tunnel ip

- modified policy on both firewalls to accept incoming connection from tunnel ip

 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors