Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Roni
New Contributor

IPSEC VPN is up but no any traffic.

Hi, I`m trying to solve a problem with STS configuration.

the tunnel has created, the vpn connections is up, but there is no traffic.

when i sent ping from comp1(first FW) to comp1(second FW), unfortunately 100% Loss. Traceroute as well go to nowhere.

Thank you.

2 REPLIES 2
brudy
New Contributor II

Hi Roni

 

I have the same problem with on of my customers.

 

We use IPsec, FortiClientEMS 6.0.3 and FortiOS 6.0.3. When we downgrade the client to 6.0.0 it works. We have not tried 6.0.1 or 6.0.2 yet.

 

What versions do you have?

 

__
Peter Bruderer
__Peter Bruderer
ede_pfau

OP, I assume "STS" means site-to-site. In this case, brudy's post would not apply.

 

You need 4 things for an IPsec VPN to work:

- the tunnel setup itself

- the Quick mode selectors in phase2

- a route to the tunnel interface

- a policy for traffic from/to the tunnel interface

 

As long as you control both sides of the tunnel (both FGTs) you can always make it work.

Please check that all of the above is working the way you intend it to be. For instance, in the policy table, you can set up traffic from - to and let FortiOS determine the policy it would use. Or in the routing table, you can check which route a specific traffic would use (or the absense of such).

Then, if all is set, we can try to debug this here, with more information supplied, and you tracing live traffic on the FGT.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors