Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SoonLeong
New Contributor

Problem: FortiGate 60D version 5.4, site 2 site VPN using dynamic DNS at both end

Hi

 

I am setting up site 2 site IPsec VPN, using the wizard provided by GUI. I am using dynamic DNS at both end, route (non-NAT) set up. The link status shows up, but I am not able to ping the other end network. When I changed one end to use static IP, I am able to ping. So long as one end is static IP the ping is ok. I confirmed by swapping the config to the other end to use static IP.

 

Questions:

1. Any suggestions on how I can debug to find out what is wrong?

2. Any suggestions on what could be wrong?

3. Does version 5.4 support site 2 site IPsec VPN using dynamic VPN at both end?

4. Does version 5.6 (latest firmware) support using dynamic VPN at both end?

 

Regards,

Soon Leong.

1 REPLY 1
mas1971
New Contributor III

SoonLeong wrote:

Questions:

1. Any suggestions on how I can debug to find out what is wrong?

2. Any suggestions on what could be wrong?

3. Does version 5.4 support site 2 site IPsec VPN using dynamic VPN at both end?

4. Does version 5.6 (latest firmware) support using dynamic VPN at both end?

 

Hi,

 

i am using site 2 site IPsec VPN with one site static ip (FG60D) and one site ddns. I got an similar issue. The tunnel come up, but traffic is only available from one site starting. Only from the dynamic site to the static site. (This works fine, Windows RDP is useable, and so on.)

With Fortios 5.2.10 every thing was fine in both directions with the same config. Upgrading to 5.4.x and 5.6.x we got the issues. (We startet using 5.4 and go on to 5.6 after getting the issues) So i will answer your question 4.) it seams to be the same VPN code in Fortios 5.4 and 5.6. i read something about that there are a lot of changes against Fortios 5.2.10, especially using dynmic or ddns VPN. Im using VPN with static routing, not with policiy routing.

 

I opened a ticket and get support from Fortinet, but the Problem is still allive. I hope they can fix this, because going back to 5.2.10 is only a good thing for the next few month, because Fortios 5.2.10 ist end of life status.

I beleave in Fortios 5.6, there are minor bugs than 5.4.x has.

 

Regards

Martin

Best wishes out of Germany
Best wishes out of Germany
Labels
Top Kudoed Authors