Fortinet: Troubleshoot 5 IPSec Site-to-Site VPN Scenarios - FortiGate

Поделиться
HTML-код
  • Опубликовано: 2 янв 2025

Комментарии • 33

  • @jobyit
    @jobyit 2 года назад +4

    Brilliant, this would really help FortiGate engineers to fix all the s2s related issues.Awesome.......

  • @mycablebox205
    @mycablebox205 3 месяца назад +1

    newbie to fortigate, this video resolved my site-to-site vpn issue

  • @aarushsingh2006
    @aarushsingh2006 2 года назад +2

    It was really to the point. Thanks mate.

  • @vikasnayak4899
    @vikasnayak4899 Месяц назад +1

    It will help to solve S2S issues thank you

  • @khaledBouafia-p3p
    @khaledBouafia-p3p 2 месяца назад +1

    very good explanation

  • @arashvermahmood7961
    @arashvermahmood7961 5 месяцев назад +1

    just great. thanks for sharing.

  • @amitkoolmar
    @amitkoolmar 2 года назад +1

    Amazing content! Thanks so much!

  • @bjaspidey
    @bjaspidey 2 года назад +1

    Excellent video!

  • @CiZiK22
    @CiZiK22 6 месяцев назад

    Interesting video, well done ! Thanks

  • @Quick_UnBoxing0
    @Quick_UnBoxing0 Год назад +1

    Amazing 🎉

  • @ravishere-mn6no
    @ravishere-mn6no Год назад

    Thank you very much for the video !!

  • @adriantepes-qu8wm
    @adriantepes-qu8wm Месяц назад

    When you create a tunnel in Fortigate, do you have to explicitly create a firewall rule to say allow traffic (port 500, 4500) from remote gateway IP to your firewall's Public IP ?

    • @tothepointfortinet3823
      @tothepointfortinet3823  Месяц назад +1

      No you do not need a rule for port 500 or 4500(this is traffic to/from the actual fortigate itself which is implicitly allowed by default via local in policy) .
      What is required is a firewall policy referencing the ipsec tunnel interface (if that's missing then fortigate won't establish a tunnel)

    • @adriantepes-qu8wm
      @adriantepes-qu8wm Месяц назад

      @@tothepointfortinet3823 tnx

  • @smile-w5d
    @smile-w5d Год назад +1

    great job, tks!

  • @ernof4271
    @ernof4271 2 года назад

    thanks mate, very usefull information for me

  • @MahmoudMohamed-si3by
    @MahmoudMohamed-si3by 5 дней назад

    Excellent

  • @jayanvv-oi8hp
    @jayanvv-oi8hp 2 года назад +1

    great content 🤝

  • @carloscortes8761
    @carloscortes8761 10 месяцев назад +1

    i love ti, thanks

  • @netconfig999
    @netconfig999 6 месяцев назад +1

    thanks for sharing

  • @loidrama4721
    @loidrama4721 Год назад

    Sir my problem is that all Connections are up but no Incoming Data and Outgoing data were made.

    • @tothepointfortinet3823
      @tothepointfortinet3823  Год назад

      Might want to check firewall policy config, ipsec selectors and routing config. If you still have trouble check out my video on sniffer. Then it might be good to call support

  • @diwakarsawant_
    @diwakarsawant_ 2 месяца назад +1

    Good 🎉

  • @raikone14
    @raikone14 2 года назад

    tks, nice vide, if you allow me to make a question, if nat t is enable I should expect traffic in port 500 as well in phase1 ? or 4500 ? I am confuse

    • @tothepointfortinet3823
      @tothepointfortinet3823  2 года назад +2

      Yes, you should always expect traffic on port 500 regardless of NATT, NATT is specific to phase2
      Here's the ports/protocols to expect depending on whether NATT is in use or not:
      NATT NOT being used:
      phase1 = UDP 500
      phase2 = ESP (ie. IP protocol 50)
      NATT being used:
      phase1 = UDP 500
      phase2 = UDP 4500

    • @raikone14
      @raikone14 2 года назад

      @@tothepointfortinet3823 tks a lot for the reply..you are a nice person :)

  • @michaelcarreira2638
    @michaelcarreira2638 2 года назад

    Wow what great content!

  • @netadministrator1371
    @netadministrator1371 10 месяцев назад

    i already creat site to site.its successful to connect but the other side i cant ping thier ip (local ip's).

    • @arshidibrahim3781
      @arshidibrahim3781 4 месяца назад

      Kindly turn off that system firewall and ping

  • @murugansridhar7909
    @murugansridhar7909 Год назад +1

  • @shijugopinathan1086
    @shijugopinathan1086 2 месяца назад

    Thanks

  • @Zdawoud
    @Zdawoud Год назад +1

    Thanks (Y)