Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gbrits
New Contributor

IPSEC tunnel off connecting over PPPOE ISP connection

Good day .... I am not having one :)

We have a Fortigate 70C connecting to a Fortigate 300C (IPSEC VPN)

The ISP provided a 50MB Fiber internet line, and they use a PPPOE dial up "solution" to make the Internet connection "live"

 

I have installed a Fortigate 60B firewall, configured the PPPOE, added the policies, and the Line is up and running 100%

 

On the LAN side, I configured one of the public IP addresses inside the /29 range provided.

If I plug my laptop on the Public switch, configured also with one of the public IP addresses, internet works fine. So this confirm that the PPPOE setup and line and routing from ISP etc is fine.

 

But the main Fortigate 70B firewall just can't connect or make the IPSEC connection to the 300C at head office. The IPSEC config is 100%, as it was working 100%, we changed to the new ISP, worked for a week and just died.

 

ANything to look at on the 60C which does the PPPOE connection? MTU, or any IPSEC throughput rules or any help ?

3 REPLIES 3
boneyard
Valued Contributor

first off you are aware you are running old (C) / ancient (B) hardware here? which means unsupported software which doesnt get updates or security fixes. please try to get that solved as soon as possible, the nice bonus is you get Fortinet support access with better response times then a forum :) and yes im aware this specific issue is probably not hardware or software related if it did work some time ago, but still.

 

as for the issue. you tried to restart the firewall?

 

is the tunnel not up at all?

 

if the tunnel is up, does no traffic work or only some, i.e. ping?

 

you might already have found this KB article, but that is only relevant if some traffic doesn't work: https://kb.fortinet.com/k...nk.do?externalID=11731

gbrits

Good day 

Yes I am aware of all the old stuff :) Not my network and not my rules, employed to look after what is given to us to work with 

 

That out of the way :)

 

I did all the obvious things. Fortigate 60 is on, I log onto is, pppoe connection is on, Internet is fine and fast

The fortigate behind it, that initiates the IPSEC tunnel, makes connection but no traffic it seems 

boneyard
Valued Contributor

so you can't ping through the tunnel?

 

and if you just browse from behind the second FortiGate, not through the tunnel? does that work?

 

 

Labels
Top Kudoed Authors