Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

Troubleshooting
Research
Professional Opinions
Ask a Question
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE

troubleshooting Question

Fortigate 100A IPSEC VPN Draytek Vigor 2820 One way ping

Avatar of getdanonit
getdanonit asked on
VPNHardware FirewallsInternet Protocol Security
4 Comments1 Solution2753 ViewsLast Modified:
I have setup an IPSEC VPN tunnel between 2 sites. The Draytek Vigor 2820 dials the fortigate 100a and the tunnel comes up ok. I can ping all devices behind the Fortigate with no problem, but when pinging the other direction I get nothing.

Fortigate has an internal subnet 192.168.111.0/24
Draytek has an internal subnet 192.168.100.0/24

I can see on the stats of the fotigate that data is going both ways so what could be stopping me pinging the Draytek and that network.

If iI tracerout the external IP of the Draytek from behind the Fortigate it goes through as expected. If I tracert the internal IP of the Draytek it gets half way then times out.

If I tracert the Fortigate from the Draytek I get nothing, yet all pings work fine. Even exchange and rdp are working fine.

This doesn't make sense to me. What am a I missing?
ASKER CERTIFIED SOLUTION
Avatar of digitap
Commented:
This problem has been solved!
Unlock 1 Answer and 4 Comments.
See Answers