Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aguerriero
Contributor II

policy vpn with vpn concentrator not passing traffic between spokes 7.0.5

I can get a dial up vpn going and the ipsec policy works fine but spoke to spoke traffic does not work when a concentrator is added.

Debug flow shows packets ingressing from spoke1 and egressing to spoke2. The problem is that return traffic from spoke 2 is never processed by the fortigate. The flows show absolutely nothing.

The reverse path is also the same. traffic from spoke 2 to spoke 1 are received at spoke 1 but the fortigate does not process the return traffic from spoke 1.

I tried this out on 6.2.10 and the flow showed the traffaic being dropped by policy 0.  After moving to a different firewall running 7.0 I now get good policy matches but no return traffic is processed.

Capturing packets on the underlay definetely shows return traffic making it to the fortigate.

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello aguerriero,

 

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Regards,

Anthony-Fortinet Community Team.
abelio
SuperUser
SuperUser

Hello

Did you already check 'net-device' setting?
If not, here is explained in detail:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-set-net-device-new-route-based-IPsec-logic...

regards




/ Abel

regards / Abel
aguerriero

I am not using ipsec interface. net-device is not an option.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors