Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rolo
New Contributor

IPsec Between Fortinet and Mikrotik

Hello, I don't have much experience with this stuff and have a little problem if anyone can help me would be great. i have FortiGate 40F on one side and Mikrotik 2011 on another side. i managed to build IPsec between those 2 and IP sec is UP.

But there is problem i can't have ping or any kind of connection between those 2 networks. On mikrotik i have 192.168.1.0/24 network and on fortinet side i got 192.168.60.0/24 network on Lan ports. If anyone can help me to tell me what should i check to find the problem i haven't much experience with fortigate.

[link]https://ibb.co/0rnHQxN[/link] [link]https://ibb.co/JHwWsW8[/link] [link]https://ibb.co/kHKH6Lp[/link] [link]https://ibb.co/XLPxgD9[/link] [link]https://ibb.co/ysgG7Dy[/link] [link]https://ibb.co/L8vtmf7[/link] [link]https://ibb.co/q59nccM[/link]

11 REPLIES 11
Toshi_Esumi
SuperUser
SuperUser

I don't see any particular problem on the 40F config, although I would remove the second static route for 192.168/16. But it shouldn't break anything even if it's there.

I would suspect the other side, but first sniff packets on the FGT while you ping from FGT's local toward the other side. You need to disable asic offloading (set auto-asic-offload diable) on both policies in CLI to see all packets. Don't forget to reenable it after you're done.

 

Jirka1

Hi, do you have a rule on Mikrotik in NAT that allows communication between subnets? It must be placed in front of a global masquerade or NAT. 

 

 /ip firewall nat> add src-address 192.168.1.0/24 dst-address 192.168.60.0/24 action=accept

 

We operate about 20+ IPsec tunnels between Mikrotik and FGT and it's rock stable.

 

Jirka

rolo
New Contributor

Hi, Thanks for replying me, yes i've created that rule too on mikrotik side i think it should be like that 

rolo
New Contributor

Hi, Thanks for replying for me i've created that rule too on mikrotik side of course  [link]https://ibb.co/WxpJB84[/link]

ErmirMorina

Hey Jirka, 

 

So I see u have a lot of experience with IPSec between Mikrotik and FGT, i have one setup between my two sites but https traffic just doesn't seem to go through, any idea why that might happen? 

Thanks a lot in advance.

rolo

Hi thank you so much for replying on me i can provide mikrotik configuration too i have also rule to have 2 subnets connection between https://ibb.co/WxpJB84 . also i will try packet sniffing too i've never done it on fortigate so ill need some time google it :D.  any ideas what can be problem on mikrotik side i know its hard to say like this 

Jirka1
Contributor III

Did you do a double check IPsec setting on Mikrotik? Mainly DH and PFS group settings, lifetime and NAT Traversal?

I don't think the mistake will be on FortiGate's side.

 

Jirka

 

rolo
New Contributor

Hi so sorry for a late reply so here is the configuration on both side 

 

https://ibb.co/H2jKx89 https://ibb.co/344018V

supportombm
New Contributor III

Hi,

i'm not here to helping you sorry BUT next time ALWAYS HIDE your ips in every image. It's a must if they are open. Trust me.

 

Labels
Top Kudoed Authors