Hello,
we have a Fortigate 600D
I've created a new IPSec Tunnel, and, for this tunnel, a static route. But the static route is not active. I can't see it under Monitor > Routing Monitor.
With the command "get route info routing-table all" the static isn't shown, too.
With the command "get route info routing-table all" the static route is shown as inactive:
S 10.231.154.0/24 [10/0] is directly connected, VPN_Test inactive
If I change the the device from the static route to an already for a long time existing VPN, the route is working.
Thank you
AlbMin
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hey there!
First, I think that's because you use get router info routing-table database instead get route info routing-table all. This KB may help you: http://kb.fortinet.com/kb/documentLink.do?externalID=FD36417
Second, a route is inactive when is invalid for using it. Every route must fulfill with some rules to the Fortigate could use it.
You could check this KB from fortinet:
http://kb.fortinet.com/kb/documentLink.do?popup=true&externalID=FD30119&languageId=
I'm not entirely sure, but i think your VPN is down.
Check your VPN status and when is up, your route would be active.
Hope it helps!
If the phase1 is not up the route would be inactive.
diag vpn tunnel list and diag vpn gateway will show your ipsec tunnel is down.
Also the get router details will show this also;
i.e
get router info routing-table details 192.18.245.99/32
Routing entry for 192.18.245.99/32 Known via "static", distance 10, metric 0 directly connected, evpntst inactive
PCNSE
NSE
StrongSwan
Hello,
thanks for answers. You're right, the relevant VPN tunnel was never up. But the VPN tunnel I changed to for testing, was'nt up at the moment, too. But of course he was already activated in the past. Perhaps that's the decisive difference.
Just in this moment the tunnel goes up first time and now the static route is active. Great.
Thanks a lot
Greetings
AlbMin
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.