{"id":611,"date":"2020-02-25T08:35:52","date_gmt":"2020-02-25T13:35:52","guid":{"rendered":"https:\/\/increasec.com\/?p=611"},"modified":"2020-06-24T16:37:02","modified_gmt":"2020-06-24T20:37:02","slug":"fortigate-vpn-troubleshooting","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=611","title":{"rendered":"Fortigate VPN troubleshooting"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">If you are  troubleshooting a Fortinet VPN here are a few tips.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Network, Packet capture will allow you to capture data on a VPN tunnel interface.  This can be used to confirm that ping packets are being sent over the tunnel and it states explicitly that ping responses didn&#8217;t return.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"129\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/02\/image-2-1024x129.png\" alt=\"\" class=\"wp-image-612\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/02\/image-2-1024x129.png 1024w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/02\/image-2-300x38.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/02\/image-2-768x97.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/02\/image-2-710x90.png 710w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/02\/image-2.png 1412w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Start a Putty session to the Fortigate and run the following commands to produce a diagnostic output.  Recommend enabling putty is logging so you can search back in time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">diag de en<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>in Fortigate Web Gui click Monitor, IPsec monitor, Bring the tunnel selectors UP.<\/li><li>Now you will see some output on the CLI, attach the output to a Fortinet support ticket.<\/li><li>from the Fortigate console  execute ping 10.x.x.x<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"> di de dis<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">IF you have multiple VPN&#8217;s i recommend adding a filter to avoid confusion<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">diag debug reset<br>diag de app ike -1<br>diag vpn ike log filter clear<br>diag vpn ike log filter dst-addr4 (public addr of remote VPN)<br>diag debug enable<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are debugging a Remote Dial VPN you can filter by name?<br>dia deb disable<br>dia deb reset<br>dia vpn ike gateway clear<br>dia vpn ike log filter name *VPN NAME*<br>diag vpn ike log-filter dst-addr4<br>dia deb app ike -1<br>dia deb enable<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Troubleshooting Dialup VPN:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Upgrade client; have seen Forticlient 6.0 unable to get to subnets that worked correctly when upgraded to Forticlient 6.2<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In order to uninstall Forticlient you may need to unlock in the client then shutdown via the tray icon, before you get the option to uninstall in add\/remove programs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Increase you putty session lifetime<br>set system session_ttl port 22 timeout 3600<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you are troubleshooting a Fortinet VPN here are a few tips. Network, Packet capture will allow you to capture data on a VPN tunnel interface. This can be used&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[87,86,105,106],"class_list":["post-611","post","type-post","status-publish","format-standard","hentry","category-uncategorised","tag-fortigate","tag-fortinet","tag-troubleshooting","tag-vpn"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/611","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=611"}],"version-history":[{"count":9,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/611\/revisions"}],"predecessor-version":[{"id":1573,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/611\/revisions\/1573"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=611"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=611"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=611"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}