Solved

Fortigate IPSEC VPN Up but no traffic passes

Posted on 2012-03-26
2
8,891 Views
Last Modified: 2012-03-27
We have a new Fortigate 110C running current firmware.

Attached are the screen shots used to set up the VPN.  The VPN was setup using the GUI.

The link comes up but it does not pass traffic.  What am I doing wrong?
VPN-problem.pdf
0
Comment
Question by:botisys
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 8

Accepted Solution

by:
myramu earned 500 total points
ID: 37769957
Hello Botisys,

Move the ipsec policy to top of all policies and also try by enabling inbound and outbound nat. If you still face the issue use the following command to check the reason,
diag debug reset
diag debug enable
diag debug flow filter addr x.x.x.x
diag debug flow show console enable
diag debug console timestamp enable
diag debug flow trace start 50

where x.x.x.x is IP address of the trafiic initiator.

Good Luck!
0
 

Author Comment

by:botisys
ID: 37773160
Changing the Policies to Global View allowed me to move the IPSEC policy to the top. In Section View, it would not allow the policy to be moved.  NAT was not necessary.  The VPN is working now.  Thanks for your help.
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Hello All, I have been training on Multicast for a while now and whenever I start the topic , I find out that my friends /  Colleagues mention that they do not know how to test Multicast Joins. As most of the multicast would be video traffic and …
Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question