Project

General

Profile

Issue #2868

IPSec (dail up) to Fortigate (fix IP)

Added by Jack Wong 5 months ago. Updated 5 months ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
ikev1
Affected version:
5.7.1
Resolution:
No change required

Description

I have Fortigate (let say 100.100.100.100) as a gateway want dail up from Strongswan (no fix IP)
I get the IPsec up, but traffic cannot be sent. May I have your hint to solve my problem?

fortigate_screen_01.jpg (62.9 KB) fortigate_screen_01.jpg Jack Wong, 21.12.2018 06:47
capture-20181220-141030.jpg (54.5 KB) capture-20181220-141030.jpg Jack Wong, 21.12.2018 06:47
fortigate_VPN_Status.jpg (96.7 KB) fortigate_VPN_Status.jpg Jack Wong, 21.12.2018 06:47
ipsec_secrets.jpg (23.5 KB) ipsec_secrets.jpg Jack Wong, 21.12.2018 06:47
ipsec_conf.jpg (64.3 KB) ipsec_conf.jpg Jack Wong, 21.12.2018 06:47
strongswan_ifconfig.jpg (108 KB) strongswan_ifconfig.jpg Jack Wong, 21.12.2018 06:47
strongswan_ip_xfrm.jpg (89.6 KB) strongswan_ip_xfrm.jpg Jack Wong, 21.12.2018 06:47
IPTABLES.jpg (238 KB) IPTABLES.jpg Jack Wong, 21.12.2018 06:47
strongswan_screen_01.jpg (256 KB) strongswan_screen_01.jpg Jack Wong, 21.12.2018 06:47

History

#1 Updated by Tobias Brunner 5 months ago

  • Status changed from New to Feedback

You have to find out where your traffic is stuck (is it ever sent, is it received, is it forwarded, is there a response etc.). Also see HelpRequests.

#2 Updated by Jack Wong 5 months ago

Tobias Brunner wrote:

You have to find out where your traffic is stuck (is it ever sent, is it received, is it forwarded, is there a response etc.). Also see HelpRequests.

Thanks for your reply, I found that no "ip route list table 220" record after ipsec up.
How to add the SUBNET AND GATEWAY in "ip route list table 220"?

#3 Updated by Jack Wong 5 months ago

After change to ikev2, all work well. Please close my case. Thanks.

#4 Updated by Noel Kuntze 5 months ago

  • Status changed from Feedback to Closed
  • Resolution set to No change required

Also available in: Atom PDF