Hello everyone I stuck resolving one issue for our user. She uses shrew vpn client to connect to vpn. It is not like l2tp/ipsec connection with username password and psk. Actually I can connect to vpn eve with l2tp/ipsec. But she uses something like vpn site-to-site connection. I noticed in settings of vpn confid it has phase1 and phase2 selector and everything else what required to setup site-to-site connection
so whenever she clicks connect this soft stucks at “bringing up tunnel” . It may stay bringing up tunnel state many hours with no error .
i cant see any error in fortigate logs (attaced). Remote site admin told that everyone can connect so somethin preventing her connection. ..maybe my firewall.
config loaded for site 'xx.xxx.xx.xxx.vpn.vpn'
attached to key daemon ...
peer configured
iskamp proposal configured
esp proposal configured
client configured
local id configured
remote id configured
server cert configured
client cert configured
client key configured
bringing up tunnel ...
This is my rule config
config firewall policy
edit 20
set name "Allow VPN Connection"
set uuid 1d502eac-2a52-51e9-9c5c-9403aa57bb56
set srcintf "port10"
set dstintf "port9"
set srcaddr "all"
set dstaddr "Allowed VPN servers"
set action accept
set schedule "always"
set service "vpn-tunneling"
set logtraffic all
set logtraffic-start enable
set capture-packet enable
set fsso disable
set nat enable
next
end
the host is windows 8 pc
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Seems it is not fortigate issue.
Thanks for viewing question :)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.