AWS Fortigate S2S directionality issue...

0

I have an AWS to on-premise Fortigate site-to-site tunnel (static routing) configured and up. I could only pass traffic in the AWS-to-Fortigate direction after sending traffic in the Fortigate-to-AWS direction. Why is this? Is there a tunnel activity timeout involved?

gefragt vor 2 Jahren534 Aufrufe
3 Antworten
0

Hello,

Suggest checking the troubleshooting steps listed in the below Knowledge center article:

https://aws.amazon.com/premiumsupport/knowledge-center/vpn-cgw-vpg-traffic/

profile pictureAWS
EXPERTE
beantwortet vor 2 Jahren
0

When I see this is says to me "NAT is happening in the Fortigate firewall". Make sure that you've disabling any address translation on the VPN connection or for the IP ranges in question.

The other common issue is that the AWS side is not configured to initiate the VPN connection which means it must be created from the Fortigate side. Our documentation talks to how to configure tunnel initiation: https://docs.aws.amazon.com/vpn/latest/s2svpn/initiate-vpn-tunnels.html

profile pictureAWS
EXPERTE
beantwortet vor 2 Jahren
0

hello, review the rule of security group in the interface to internet. this could be have allow trafic explicity. I was have something like that.

best regards

beantwortet vor 2 Jahren

Du bist nicht angemeldet. Anmelden um eine Antwort zu veröffentlichen.

Eine gute Antwort beantwortet die Frage klar, gibt konstruktives Feedback und fördert die berufliche Weiterentwicklung des Fragenstellers.

Richtlinien für die Beantwortung von Fragen