Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Fortigate 620B Gateway to Gateway

Hi Guys We are working at a Remote Branch and are trying to get our site to site vpn up and running. I have used the IPSEC VPN Guide handbook v3 for research/reference. We have 2* Fortigate 620b and have established the phase 1 and phase 2 the link comes up and turns green and on the face of it all seems well (can see traffic in the counter)but traffic from Site A never reaches Site B even though the traffic log shows it as allowed. I thought there was a issue with the routes but im getting confused to wheather i should be using a static route if im using Policy Based VPN? Anyway i tried without the route but the problem still persists. What i have observed. From Site A cant ping Site B devices Front Site A cant tracert to Site B devices I can see the trace going to the internal interface on our Site A LAN however it just seems to time out. In traffic log it shows as allowed. From Site B can ping DC at Site A From Site B can traceroute from Fortigate CLI to DC at Site A (appears as 1hop) We have our IPSEC policies at sequence 1 in the firewall policy. Addresses from remote network ranges exist in both Fortigate Units. Not tried to debug yet but i presume that might be the next step? Thanks in advance. Forgot to mention using FortiOS 4 v4.0,build0291,100824 (MR2 Patch 2)
5 REPLIES 5
ede_pfau
SuperUser
SuperUser

Hi, and welcome to the forums. The config you' ve given is too vague to judge upon. From the snippets I deduct: - why in the world do you use policy mode IPsec VPNs? I can' t see why this would be mandatory in your case, and route/interface based VPN is way easier to understand and configure. PB VPN is considered ' legacy' and FortiOS specific. - if you don' t even post any one line of your config, like VPN phase1 and phase2, QMs, and the corresponding policies, we can only resort to mind reading. Hmm, no reception today. - have you read on the VPN examples in the FortiOS Handbook? if you follow these basic examples it should work within minutes. Get it from docs.fortinet.com Come back with more infos and we' ll do our best. Aside: I always wonder how one can buy 5-figure equipment and NOT have a trained person set up the initial configuration. If it' s straightforward, it won' t cost much. If it' s complicated you get the job done in a few hours (that is percent of the system' s cost). And you will learn a lot as well. Sorry, today is my rant-day, must be the weather.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Not applicable

Agreed the weather is poor here also. Sorry for not posting the config/policies i will try the route based VPN method from the handbook. Good comment about the expensive firewall and lack of proper knowledge on-site to implement the deployment. I have queried this also. Unfortunately i have no control over the budgets. Thanks once again.
Not applicable

Just to update you i have now figured out the Route based vpn policy. Everything is now working and my DC are now back online. Thanks for the tip about route based vpn being easier.
ede_pfau
SuperUser
SuperUser

I' m glad that you' ve got it running in time. Documentation is really good on the Fortigates, with primarily the FortiOS Handbook and recently, the Cookbook. They try to give working examples of the top-most deployment scenarios to get their customers started easily. As to the budgets, I know what you mean. One day you get two fat appliances dumped on your table with a remark " you' re IT, so you can run it" . To cut the implementation by the vendor is cheaper but it costs.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
rwpatterson
Valued Contributor III

Your salaried time is already budgeted. They will waste it all year long.....

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Labels
Top Kudoed Authors