Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site-to-Site VPN Sophos to Fortigate

Hello,

I want a Site-to-Site VPN from Sophos UTM9 to Fortigate 60D but i cant ping or access the other Network.

In Fortinet and Sophos the VPN Tunnel is up.

 VPN Log:

2017:02:15-10:37:53 sg125 pluto[12404]: "S_VPN-Site-Ruf-SChlenker" #4: ignoring informational payload, type IPSEC_INITIAL_CONTACT
2017:02:15-10:37:53 sg125 pluto[12404]: "S_VPN-Site-Ruf-SChlenker" #4: Peer ID is ID_IPV4_ADDR: '91.57.74.146'
2017:02:15-10:37:53 sg125 pluto[12404]: "S_VPN-Site-Ruf-SChlenker" #4: Dead Peer Detection (RFC 3706) enabled
2017:02:15-10:37:53 sg125 pluto[12404]: "S_VPN-Site-Ruf-SChlenker" #4: sent MR3, ISAKMP SA established
2017:02:15-11:21:37 sg125 pluto[12404]: "S_VPN-Site-Ruf-SChlenker" #5: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #2 {using isakmp#4}
2017:02:15-11:21:37 sg125 pluto[12404]: "S_VPN-Site-Ruf-SChlenker" #5: sent QI2, IPsec SA established {ESP=>0x6bba2b77 <0x47d13fbf DPD}
2017:02:15-11:27:02 sg125 pluto[12404]: "S_VPN-Site-Ruf-SChlenker" #6: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #3 {using isakmp#4}
2017:02:15-11:27:02 sg125 pluto[12404]: "S_VPN-Site-Ruf-SChlenker" #6: sent QI2, IPsec SA established {ESP=>0x6bba2b78 <0xf708dcf0 DPD}
2017:02:15-12:10:08 sg125 pluto[12404]: "S_VPN-Site-Ruf-SChlenker" #7: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #5 {using isakmp#4}
2017:02:15-12:10:08 sg125 pluto[12404]: "S_VPN-Site-Ruf-SChlenker" #7: sent QI2, IPsec SA established {ESP=>0x6bba2b79 <0xaf2d81aa DPD}
2017:02:15-12:13:45 sg125 pluto[12404]: "S_VPN-Site-Ruf-SChlenker" #8: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #6 {using isakmp#4}
2017:02:15-12:13:45 sg125 pluto[12404]: "S_VPN-Site-Ruf-SChlenker" #8: sent QI2, IPsec SA established {ESP=>0x6bba2b7a <0x4d3a34ef DPD}
 
 
With best regards 
Manuel


This thread was automatically locked due to age.
Parents
  • Hi, Manuel, and welcome to the UTM Community!

    That all looks perfect.  Do you have 'Automatic firewall rules' checked?

    There are two tricks:

    1. Pinging, trace route, etc. are regulated on the 'ICMP' tab of 'Firewall'.
    2. The "Any" Service includes only TCP & UDP.  ICMP and other IP protocols are not included.

    Did that help?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hello, 

    Thanks for the reply. 

    I already enabled ICMP in Sophos. Do i need a rule in the tab of Firewall in Sophos ? 

     

    In the Fortigate i created the IPsec with the Wizard. The Wizard create a Firewall rule automatically.

    The main reason we want a VPN Tunnel is that we are preparing the new Clients for the Costumer and we want to integrate them into the domain.

    If you need Information just ask :)

     

    with best regards

    Manuel 

Reply
  • Hello, 

    Thanks for the reply. 

    I already enabled ICMP in Sophos. Do i need a rule in the tab of Firewall in Sophos ? 

     

    In the Fortigate i created the IPsec with the Wizard. The Wizard create a Firewall rule automatically.

    The main reason we want a VPN Tunnel is that we are preparing the new Clients for the Costumer and we want to integrate them into the domain.

    If you need Information just ask :)

     

    with best regards

    Manuel 

Children
  • The IPsec log says that the connection is made.  Start by doing #1 in Rulz.  Does that reveal anything?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?