IPsec VPN Is Up But Network Is Not Reachable
IPsec VPN Is Up But Network Is Not Reachable
Products
FortiGate
Description
The purpose of this article is to aid in troubleshooting network connectivity via IPSEC VPN. In this scenario the site to
site VPN between two FortiGates and the tunnel status is up however, both local and remote subnets are not able to
reach each other or only one way communication is working
Solution
172.16.0.0/24 local LAN -----FGT A------IPSEC VPN----- FGT B --- Remote lan 192.168.1.0/24
1. Phase2 selector: Make sure the respective source and destination ip is present in phase2 selector configured on
the FortiGate units and phase2 selector is up
If there are multiple phase2 selectors configured use the following command:
Example :
2. Route: On both FortiGates should have an active route to the remote subnets
FortigateA:
FortiGateB:
3. Policy Routing: If there policy routing applied to a specific respective source or destination create a policy route to
the respective source and destination subnets with interface as vpn tunnel and keep the policy route on top.
4. Firewall Policies: Make sure there is LAN to VPN and VPN to LAN allow policies configured on both the FortGate
with respective source / destination addresses and services.
Please note: For the LAN to VPN policy, keep NAT disabled and VPN to LAN keep PAT enabled
Example : To analyse a ping from 172.16.0.1 to 192.168.1.1 use the following command:
If the above fails, please raise a technical assistance ticket and attach the configuration of the FortiGate devices,
network diagram and debug outputs of below commands.
Run the below commands on both FortiGates and initiate the communications to capture traffic flow :
SSH 1:
SSH 2: