Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

vpn connection successful - file sharing works, but no remote dekstop, ssl or ping from outside net.

Hi Everybody, hope that somebody can help me with this problem. Intro I' ve managed to set up a ipsec vpn conection following the example given by fortinet " dial-up vpn example" - except for the " set single-source enable" the entire configuration match the one given by fortinet. i have defined no other rules, for inbound traffic og outbound traffic. the reason for not typing the " set single-source" is that the firmware is old, and i cant find a ftp server where i can download the new firmware. THE PROBLEM I' m able to use windows filesharing with my vpn, but i' m unable to use remote desktop (microsoft), or connect to a machine on the internal lan using ssh. I' m able to ping the external client from with in the network, but i' m unable to ping the internal servers, from the external client. if i do a tracert i command prompht i get to the firewall, and then the rest of the time it just shows stars, as if i' m unable to get through the firewall. Please help Any comments are welcome, on how to solve the problem or direction to where i might download the new firmware. kind Regards Carl
12 REPLIES 12
Not applicable

Here is some more info: This is the result of the debug console on the fortigate. This result comes, after i do a tracert from the client connection through vpn: 2006-01-13 14:42:23 Comes EX.EX.EX.EX:500->GX.GX.GX.GX:500,ifindex=3, external, vf_id=0.... 2006-01-13 14:42:23 Exchange Mode = 5, Message id = 0xFEC228C6, Len = 92 2006-01-13 14:42:23 ####### ISAKMP INFO ########## 2006-01-13 14:42:23 Received Payloads=2006-01-13 14:42:23 HASH2006-01-13 14:42:23 Notif2006-01-13 14:42:23 2006-01-13 14:42:23 ######### Receive Information Payload(Protected)######### 2006-01-13 14:42:23 protocol_id=1, notify_msg=36136 (DPD_PROBE), ispi_size=16 2006-01-13 14:42:23 spi=2006-01-13 14:42:23 722006-01-13 14:42:23 d92006-01-13 14:42:23 c22006-01-13 14:42:23 b62006-01-13 14:42:23 d82006-01-13 14:42:23 bb2006-01-13 14:42:23 982006-01-13 14:42:23 512006-01-13 14:42:23 d82006-01-13 14:42:23 a72006-01-13 14:42:23 f62006-01-13 14:42:23 962006-01-13 14:42:23 482006-01-13 14:42:23 0f2006-01-13 14:42:23 fc2006-01-13 14:42:23 532006-01-13 14:42:23 2006-01-13 14:42:23 Msg=2006-01-13 14:42:23 002006-01-13 14:42:23 002006-01-13 14:42:23 002006-01-13 14:42:23 052006-01-13 14:42:23 2006-01-13 14:42:23 Send IKE Packet(DPD probe):GX.GX.GX.GX:500(if3) -> EX.EX.EX.EX:500, len=92 2006-01-13 14:42:23 I have replaced my ip. GX is the ip of the external interface of the firewall EX is the ip of the client trying to connect. Regards Carl
Not applicable

Same issue for me... Does anyone have a solution ? pleaz help us :)
Not applicable

okay so i finally solved the problem. okay i had created 2 address spaces on the firewall running from 192.168.2.1 and a netmask of 255.255.255.128, and a nother running from 192.168.2.128 and netmask 255.255.255.128. using these ipaddress spaces presented a problem since the default gateway of the fortigates internal side is at 192.168.2.1. so changing the address spaces from 192.168.2.0/255.255.255.128 and 192.168.2.128/255.255.255.128 everywhere both on the firewall and on the forticlient solved the problem. i just want to thank everybody who tried to help. Kind Regards Carl
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors