Brilliant, this would really help FortiGate engineers to fix all the s2s related issues.Awesome.......
@mycablebox2054 ай бұрын
newbie to fortigate, this video resolved my site-to-site vpn issue
@sk198359 күн бұрын
In our organization since 10 days one issue coming...firewall suddenly becomes unreachable and when we make 1 tunnel disable then only it comes up...for 15 location this is issue...can u guide what could be issue
@aarushsingh20062 жыл бұрын
It was really to the point. Thanks mate.
@adriantepes-qu8wm2 ай бұрын
When you create a tunnel in Fortigate, do you have to explicitly create a firewall rule to say allow traffic (port 500, 4500) from remote gateway IP to your firewall's Public IP ?
@tothepointfortinet38232 ай бұрын
No you do not need a rule for port 500 or 4500(this is traffic to/from the actual fortigate itself which is implicitly allowed by default via local in policy) . What is required is a firewall policy referencing the ipsec tunnel interface (if that's missing then fortigate won't establish a tunnel)
@adriantepes-qu8wm2 ай бұрын
@@tothepointfortinet3823 tnx
@vikasnayak48992 ай бұрын
It will help to solve S2S issues thank you
@khaledBouafia-p3p3 ай бұрын
very good explanation
@bjaspidey2 жыл бұрын
Excellent video!
@MahmoudMohamed-si3byАй бұрын
Excellent
@loidrama4721 Жыл бұрын
Sir my problem is that all Connections are up but no Incoming Data and Outgoing data were made.
@tothepointfortinet3823 Жыл бұрын
Might want to check firewall policy config, ipsec selectors and routing config. If you still have trouble check out my video on sniffer. Then it might be good to call support
@arashvermahmood79616 ай бұрын
just great. thanks for sharing.
@amitkoolmar2 жыл бұрын
Amazing content! Thanks so much!
@raikone142 жыл бұрын
tks, nice vide, if you allow me to make a question, if nat t is enable I should expect traffic in port 500 as well in phase1 ? or 4500 ? I am confuse
@tothepointfortinet38232 жыл бұрын
Yes, you should always expect traffic on port 500 regardless of NATT, NATT is specific to phase2 Here's the ports/protocols to expect depending on whether NATT is in use or not: NATT NOT being used: phase1 = UDP 500 phase2 = ESP (ie. IP protocol 50) NATT being used: phase1 = UDP 500 phase2 = UDP 4500
@raikone142 жыл бұрын
@@tothepointfortinet3823 tks a lot for the reply..you are a nice person :)
@CiZiK227 ай бұрын
Interesting video, well done ! Thanks
@Quick_UnBoxing0 Жыл бұрын
Amazing 🎉
@jayanvv-oi8hp2 жыл бұрын
great content 🤝
@ravishere-mn6no Жыл бұрын
Thank you very much for the video !!
@smile-w5d Жыл бұрын
great job, tks!
@michaelcarreira26383 жыл бұрын
Wow what great content!
@netadministrator137111 ай бұрын
i already creat site to site.its successful to connect but the other side i cant ping thier ip (local ip's).