This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RED Traffic on IPSec VPN: XG210 17.5.8 and FortiGate 61E

Hi team,

Need your assistant on something here.

My current setup is that i have an IPSEC VPN connecting XG>FortiGate which is working OK. But now i cannot reach RED network (Remote site network) from FortiGate network and vise versa. Am clueless on how to approach this. 

Please help. I'm new to Sophos

Thanks            



This thread was automatically locked due to age.
Parents
  • Hello Chacha,

    Have you configured the RED network on your IPSec VPN? For traffic to flow over an IPSec tunnel, the necessary SA will need to be established.

    Under Configure > VPN > IPsec connections, did you include the RED network in the local subnet field? Please note on the FortiGate side it will need to be in equivalent local subnet field as well.

    If you do have this configured, the next step would be to confirm that the SA's are established correctly. This can be done by clicking on the little blue "i" icon next to the connection status circle. It is circled in red in the below image.

     

    It will present the following page. Please ensure that the subnets listed match what is configured.

    If the above looks correct, then the next step would be to perform a packet capture to verify what is happening to the traffic. The following knowledge base article covers how to use the packet capture feature.

    https://community.sophos.com/kb/en-us/123189

    Bryan Yang
    Community Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

  • Appreciate Yang for quick response.

    Yes i have added RED network to IPSEC tunnel as shown below

    An the link appears to be up but nothing seem to reach either side.

    Thanks

  • Chacha,

    are you able to ping from Fortinet the red network? And vice-versa?

    Use the traceroute command to understand where the traffic is going through. Use also tcpdump.

    Regards

Reply Children