Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
theengineer
New Contributor

IPSEC Phase 1 and Phase 2 is up but return traffic not observed on Fortigate

Hi,

 

Issue is as above. Peering firewall is a Cisco Firepower.

Site A - FW A (Fortigate) <IPSEC tunnel> FW B (Cisco Firepower) - Site B

 

IPSEC P1, P2 is up and green. We're attempting SSH to reach Site B machine from Site A. We are seeing the traffic leaving from site A, routed through the tunnel interface via a diagnose sniffer packet, and from the Site B machine tcpdump we are seeing the Syn traffic reaching the machine and return traffic sent. FW B's administrator is seeing the return traffic from Site B as well and forwards it back to Site A, but we're not seeing the traffic on Fortigate (FW A) and causing a timeout of the SSH attempt either from diagnose sniffer packet, network capture from the Fortigate or a diagnose debug flow. 

 

I've been scratching my head and not too sure on what's the next step I could take, so any feedback or questions is appreciated.

 

Thanks in advance.

3 REPLIES 3
darthro132
New Contributor

We had the same issue, I worked with Fortinet support and tech support for the other side and we couldn't figure it out either.  What we ended up doing was migrating the tunnel off of our secondary ISP to our Primary and it came up.

ntaneja
Staff
Staff

Hi theengineer

 

Please run sniffer for both side public IP address and check if you see in and out esp packets on FGT A.
It's possible that ISP on site A FGT which is used to bind this vpn tunnel is blocking incoming esp traffic.


Thanks

Vichu_94
Staff
Staff

Hi the engineer,

 

Are you able to do ssh if the traffic is being initiated from Site B side? Is the flow of traffic same.

 

Please take a wireshark capture on FGT by initiating the traffic from Site A.

diag snif packet any 'host <remote_side_public_ip> and esp' 6 0 l

 

Also take the wireshark capture on both the end.

 

Please share the output cmd of phase2 selectors:-

diag vpn tunnel list name <Phase1_name>

 

 

Vishal P
Labels
Top Kudoed Authors