fortigate to pfsense ipsec vpn issue

ubercal

Expert Member
Joined
Dec 5, 2005
Messages
4,323
Reaction score
1,556
Hi,

Scenario .......

Needing to link my on-prem site to azure.On site i have a fortigate and have setup an ipsec vpn to a azure pfsense virtual appliance.The vpn tunnel comes up fine , and i can ping pcs from my azure network to my on-prem pcs fine.However i cant ping from pcs in my on-prem network to the azure pcs.Is there some bug , or what ? Been banging my head on this for a few days.
 
Check you have a incomming policy from azure on your fortigate :P
 
Check you have a incomming policy from azure on your fortigate :p

you referring to the firewall policy ? I Have an inbound and outbound policy on the forti to allow ipsec traffic both ways.The inbound is working , as traffic is following from azure to fortigate , however no traffic outbound from forti to azure.
 
What does a diag debug flow show?
The output of this should give a good indication of where it has issues

What does a diag sniffer show?
At a minimum you should see encrypted packets leaving when you ping
 
Hmm if you used custom setup on the Forti make sure you create a static route then to azure via the vpn interface.
 
Hmm if you used custom setup on the Forti make sure you create a static route then to azure via the vpn interface.

done that :X3:

I might throw this chinese pfsense out and test using 2 fortigates , cause it just doesnt make any sense.
 
ok fixed it , was some funky routing happening on the forti.
 
Top
Sign up to the MyBroadband newsletter
X