Hot!Hub and Spoke - I don´t get it

Author
AndreasMaier
New Member
  • Total Posts : 10
  • Scores: 0
  • Reward points: 0
  • Joined: 2005/01/03 11:05:25
  • Status: offline
2017/12/05 04:01:33 (permalink)
0

Hub and Spoke - I don´t get it

Hi everybody,
 
I have big problems in understanding hub and spoke VPN.
The Hub i a FGT 60C with OS 5.2 Patch 11
The Spokes are two third-party Routers (AVM Fritzbox 4020, german manufacturer) as dialup-IPSEC-connections
 
What i have is:
two route-based IPSEC-Tunnels from the Fortigate to those two routers.
I can ping from the Network behind the hub to the Network behind each spoke and from each Network behind the spoke the the Network behind the hub
 
so far, so good but i am unable to get a ping from spoke to spoke. What I tried:
 
- create a Zone containing both spoke ipsec Interfaces and disable "block intra-Zone-traffic"
- create a Zone containing both spoke ipsec Interface, leave "block intra-Zone-traffic" and create a policy from Zone to Zone  always all accept, NAT enabled
- create each pair of security policies spoke1 to spoke2 spokelan1 to spokelan2 akways all accept, NAT enbaled
 
whatever I´m trying, i can´t get this working
 
When i trace data package from spoke1 lan Client to spoke2 it Ends at the spoke1 router, so i assume the packet is being transfered into the tunnel
 
Any good advice?
 
Regards
 
Andreas Maier
#1

5 Replies Related Threads

    MasterBratac
    Gold Member
    • Total Posts : 217
    • Scores: 2
    • Reward points: 0
    • Joined: 2007/01/09 15:02:48
    • Location: Germany
    • Status: offline
    Re: Hub and Spoke - I don´t get it 2017/12/05 05:28:01 (permalink)
    0
    Hi,
     
    I'm also from germany, and I know FritzBoxes ...
    Did you set up the route to the other spokes lan to point at the ipsec tunnel in each spoke?
    See: https://avm.de/service/fr...r-FRITZ-Box-zugreifen/
    #2
    emnoc
    Expert Member
    • Total Posts : 4838
    • Scores: 294
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: Hub and Spoke - I don´t get it 2017/12/05 07:10:42 (permalink)
    0
    I would do the following, 
     
    1> cli diag debug flow
     
     
    2 >monitor the route table for the  SRC/DST ( the diag debug flow will show what matched or dropped )
     
    3> check fwpolicy( the diag debug flow would show what's match if any )
     
    4>check the phase2 SA for the spoke1 to hub and spoke2 for the interesting traffic between the SRC/DST
     

    PCNSE6,PCNSE7, ACE, CCNP,FCNSP,FCESP,Linux+,CEH,ECSA,SCSA,SCNA,CISCA email/web
    #3
    AndreasMaier
    New Member
    • Total Posts : 10
    • Scores: 0
    • Reward points: 0
    • Joined: 2005/01/03 11:05:25
    • Status: offline
    Re: Hub and Spoke - I don´t get it 2017/12/05 23:30:00 (permalink)
    0
    Hi together,
     
    yes, i configured the Fritzboxes following that article you mentioned.
     
    Diag debug flow shows me this:
     
    FGT60C-# id=20085 trace_id=5 func=print_pkt_detail line=4479 msg="vd-root
    received a packet(proto=1, 192.168.124.101:1->192.168.121.11:8) from FritzBox4_0
    . code=8, type=0, id=1, seq=13."
    id=20085 trace_id=5 func=resolve_ip_tuple_fast line=4542 msg="Find an existing s
    ession, id-0002bf59, original direction"
    id=20085 trace_id=5 func=ipsecdev_hard_start_xmit line=121 msg="enter IPsec inte
    rface-FritzBox1_0"
    id=20085 trace_id=5 func=ipsec_common_output4 line=625 msg="No matching IPsec se
    lector, drop"
    id=20085 trace_id=6 func=print_pkt_detail line=4479 msg="vd-root received a pack
    et(proto=1, 192.168.124.101:1->192.168.121.11:8) from FritzBox4_0. code=8, type=
    0, id=1, seq=14."
    id=20085 trace_id=6 func=resolve_ip_tuple_fast line=4542 msg="Find an existing s
    ession, id-0002bf59, original direction"
    id=20085 trace_id=6 func=ipsecdev_hard_start_xmit line=121 msg="enter IPsec inte
    rface-FritzBox1_0"
    id=20085 trace_id=6 func=ipsec_common_output4 line=625 msg="No matching IPsec se
    lector, drop"
     
    As far as i can see my traffic wants to be routet to the right interface (192.168.121.0 is behind FritzBox1 and 192.168.124.0 is behind Fritzbox4) but then dropped because of "No matching IPsec se
    lector" but why?
    #4
    MasterBratac
    Gold Member
    • Total Posts : 217
    • Scores: 2
    • Reward points: 0
    • Joined: 2007/01/09 15:02:48
    • Location: Germany
    • Status: offline
    Re: Hub and Spoke - I don´t get it 2017/12/06 00:41:51 (permalink)
    0
    "No matching IPsec selector, drop" is usually a problem with local and remote networks in the ipsec phase 2.
    I dont know exactly how this is configured in the FritzBox routers.
    You have to set up 0.0.0.0/0 as local and remote in phase2 or create two phase2 rules matching source and target network.
    #5
    emnoc
    Expert Member
    • Total Posts : 4838
    • Scores: 294
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: Hub and Spoke - I don´t get it 2017/12/07 11:57:19 (permalink)
    0
    Yeah, look your PH2  src/dst subnet over at the fritzbox and match the  fgt to the cfg.
     
    Ken

    PCNSE6,PCNSE7, ACE, CCNP,FCNSP,FCESP,Linux+,CEH,ECSA,SCSA,SCNA,CISCA email/web
    #6
    Jump to:
    © 2018 APG vNext Commercial Version 5.5