Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
arno974
New Contributor

pass internet trafic of all the differents vlan in aVPN dialup ipsec

hello

i have 2 fortigate 60F

-one in headquarter with a VPN server Dial up

-one remote with site to site vpn configure to outgoing traffic via the VPN to the headquater.

i use the wizard to configure on the 2 routers.. everything has been created (policy, backhole...)

 

all is ok, and functionnal on vlan1 ... and have internet and the public IP is the IP of the haedquarter.

 

but the another vlan (2,3...) of the remote site doesnt go on internet;

i can ping the public adress of the headquarter when i am on the problematic vlan's

 

the goal is to have all of the vlan go throught VPN and go on internet with the public IP of the headquater.

 

ps : i dont have vlan on the headquarter .. only vlan1

ps: when i bring down the vpn ... all the vlan go the internet via the local connexion (remote site)

1 REPLY 1
saleha
Staff
Staff

Hi,

 

Thank you for reaching out. This sounds like a traffic issue. I recommend checking the config first making sure vlan2 and 3 subnets are configured as phase 2 selectors on the ipsec tunnel on the spoke as local subnets and on the ipsec tunnel on the hub as remote subnets as well as checking static routes are correct for those 2 vlans and offcourse the firewall policies. Other than that you can troubleshoot the issue further by running the sinffer and debug flow commands below on both the hub and the spoke simultaneously to find out where does the traffic stop:
cli(1):

# diag sniffer packet any "host <dst address> and icmp" 4 0 l ------------ assuming you are testing the issue with icmp packet

 

cli(2):

di de reset

di de flow filter addr <dst address>

di de flow filter proto 1 ------------------ icmp protocol

di de flow trace start 10

di de en

 

Thank you,

saleha

Labels
Top Kudoed Authors