?
Solved

Fortigate IPSEC VPN Up but no traffic passes

Posted on 2012-03-26
2
Medium Priority
?
9,113 Views
Last Modified: 2012-03-27
We have a new Fortigate 110C running current firmware.

Attached are the screen shots used to set up the VPN.  The VPN was setup using the GUI.

The link comes up but it does not pass traffic.  What am I doing wrong?
VPN-problem.pdf
0
Comment
Question by:botisys
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 8

Accepted Solution

by:
myramu earned 1500 total points
ID: 37769957
Hello Botisys,

Move the ipsec policy to top of all policies and also try by enabling inbound and outbound nat. If you still face the issue use the following command to check the reason,
diag debug reset
diag debug enable
diag debug flow filter addr x.x.x.x
diag debug flow show console enable
diag debug console timestamp enable
diag debug flow trace start 50

where x.x.x.x is IP address of the trafiic initiator.

Good Luck!
0
 

Author Comment

by:botisys
ID: 37773160
Changing the Policies to Global View allowed me to move the IPSEC policy to the top. In Section View, it would not allow the policy to be moved.  NAT was not necessary.  The VPN is working now.  Thanks for your help.
0

Featured Post

Optimum High-Definition Video Viewing and Control

The ATEN VM0404HA 4x4 4K HDMI Matrix Switch supports 4K resolutions of UHD (3840 x 2160) and DCI (4096 x 2160) with refresh rates of 30 Hz (4:4:4) and 60 Hz (4:2:0). It is ideal for applications where the routing of 4K digital signals is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When posting a question about a Cisco ASA, Cisco Router or Cisco Switch, it can aid diagnosis if a suitably sanitised copy of the config is provided. It is much better to leave as much of the configuration as original as possible, as it could be tha…
Hello All, I have been training on Multicast for a while now and whenever I start the topic , I find out that my friends /  Colleagues mention that they do not know how to test Multicast Joins. As most of the multicast would be video traffic and …
In this video you will find out how to export Office 365 mailboxes using the built in eDiscovery tool. Bear in mind that although this method might be useful in some cases, using PST files as Office 365 backup is troublesome in a long run (more on t…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
Suggested Courses
Course of the Month13 days, 7 hours left to enroll

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question