Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fabioloc
New Contributor

ICMP over Tunnel IPSEC

Hi. Sorry for my english, please.. ;-) I configured my fortigate 110c to establish a Tunnel IPSEC with a Cisco PIX (and i can' t manage this..). The VPN works fine, but the person who configure the PIX say me 2 things: - the first, to enable ICMP inbound over the tunnel IPSEC. - second, he say that the VPN goes UP only if the connections were generated inside my network. I' m tryng to resolve this issues, can you help me? Is my first experience with a tunnel IPSEC with Fortigate.. Thank you very much!! Fabio Locati. fabio.locati@atu.it
3 REPLIES 3
ede_pfau
SuperUser
SuperUser

Hi, assuming you have created the VPN in ' interface-mode' (in phase1) then allowing ICMP in is configured in the policy ' tunnel' -> ' internal' . Well, that depends a bit on what target he wants to ping. Second, VPN Up on outgoing traffic only is common. The PIX is configured as a dial-in VPN server then. Is that a problem for you? Or the Cisco guy?

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
fabioloc

Thanks Ede! I' ll try the first for ICMP problem. And I' ll also try to understand if the problem is of the other guy .... ;-) Thank you, Fabio
emnoc
Esteemed Contributor III

For the later the asa/pix can be configured for bi-direction, answer or originate only. So traffic that initiate the vpn session can be one of the 3 options. By default it' s bi-directional unless you define this under the crypto map for that peer/instance. It' s not quite clear as to what your doing on the 1st question. Allowing icmp thru a fwpolicy is good , but depending on what the PIX guy is doing & on his end, this might fail.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors