Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mgsuzen
New Contributor

iPSec VPN same Subnets

Hi,

 

I have 2 fotrigate UTMs. One of then is 300c V.5.2 other is 50B v4.0.  I have a different problem for making ipSec VPn. http://docs.fortinet.com/uploaded/files/1692/creating-a-VPN-with-overlapping-subnets.pdf this document can't work for network.

 

On site 1 (300c) public ip is 212.156.33.X, local ip is 10.121.0.0/20 (255.255.240.0), 10.212.0.1 ip local interface is 300 C fortigate

On site 2 (50B) public IP is 212.175.55.X, local ip is 10.212.6.0/20 (255.255.240.0), 10.212.6.1 ip local interface is 50 B fotigate

 

I have read document the above documents link and apply both fortigates. IPsec VPN bridge is UP but there are no any ping or other tarffic site 1 and site 2.

 

Please help me.

 

(PS: Sorry for my english.) 

2 REPLIES 2
gschmitt
Valued Contributor

Did you create policies allowing traffic in/out on both sides?

Did you set routes on both sides?

Johan_Witters
Contributor

If you have checked the configuration for errors, I would test following:

1) perform a traceroute between the 2 locations. If it works the issue is solved :) , if not proceed with 2

2) run a diag sniffer on your vpn interface (diag sniffer packets <vpn interface> <filter eg ICMP> <loglevel eg 6> 300. check if traffic passes over the vpn

3) check if the traffic matches correct policies and route entries:

diag debug flow filter ...

diag debug flow show console enable

diag debug ena

diag debug flow trace start 100

 

it should indicate if traffic is taking the correct path and if it matches a security policy.

Johan Witters

Network & Security Engineer

FCNSP V4/V5

 

BKM NV

Johan Witters Network & Security Engineer FCNSP V4/V5 BKM NV
Labels
Top Kudoed Authors