AWS Fortigate S2S directionality issue...

0

I have an AWS to on-premise Fortigate site-to-site tunnel (static routing) configured and up. I could only pass traffic in the AWS-to-Fortigate direction after sending traffic in the Fortigate-to-AWS direction. Why is this? Is there a tunnel activity timeout involved?

已提问 2 年前534 查看次数
3 回答
0

Hello,

Suggest checking the troubleshooting steps listed in the below Knowledge center article:

https://aws.amazon.com/premiumsupport/knowledge-center/vpn-cgw-vpg-traffic/

profile pictureAWS
专家
已回答 2 年前
0

When I see this is says to me "NAT is happening in the Fortigate firewall". Make sure that you've disabling any address translation on the VPN connection or for the IP ranges in question.

The other common issue is that the AWS side is not configured to initiate the VPN connection which means it must be created from the Fortigate side. Our documentation talks to how to configure tunnel initiation: https://docs.aws.amazon.com/vpn/latest/s2svpn/initiate-vpn-tunnels.html

profile pictureAWS
专家
已回答 2 年前
0

hello, review the rule of security group in the interface to internet. this could be have allow trafic explicity. I was have something like that.

best regards

已回答 2 年前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则