AWS Fortigate S2S directionality issue...

0

I have an AWS to on-premise Fortigate site-to-site tunnel (static routing) configured and up. I could only pass traffic in the AWS-to-Fortigate direction after sending traffic in the Fortigate-to-AWS direction. Why is this? Is there a tunnel activity timeout involved?

asked 2 years ago526 views
3 Answers
0

Hello,

Suggest checking the troubleshooting steps listed in the below Knowledge center article:

https://aws.amazon.com/premiumsupport/knowledge-center/vpn-cgw-vpg-traffic/

profile pictureAWS
EXPERT
answered 2 years ago
0

When I see this is says to me "NAT is happening in the Fortigate firewall". Make sure that you've disabling any address translation on the VPN connection or for the IP ranges in question.

The other common issue is that the AWS side is not configured to initiate the VPN connection which means it must be created from the Fortigate side. Our documentation talks to how to configure tunnel initiation: https://docs.aws.amazon.com/vpn/latest/s2svpn/initiate-vpn-tunnels.html

profile pictureAWS
EXPERT
answered 2 years ago
0

hello, review the rule of security group in the interface to internet. this could be have allow trafic explicity. I was have something like that.

best regards

answered a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions