Monday, June 28, 2021

Help With FortiGate Site-to-Site Connection

Hi All,

I am looking for some help with my company's current network setup.

We have two offices, one located in Texas and one located in New York.

We currently have a FortiGate 90D in the Texas office and 60D in the New York office.

We have a site-to-site connection setup between the two that was setup prior to my arrival at the company. I am not super familiar with FortiGate and have most of my experience with Cisco and Juniper devices.

The issue we are having is all the devices in the TX office are able to reach devices in the New York office without issue, ping, RDP, etc. These devices are also able to connect out to our Azure environment and VMs that we have.

But on the other side in the New York office, the FortiGate is not able to even ping the Texas FortiGate or any other Texas devices, devices connected to our TX VPN, or any of our Azure devices (including our DNS servers).

As far as I can tell it looks like everything is configured correctly on both sides and routing table includes routes to our Azure and Texas environments and looks like the access list is configured correctly to allow traffic to pass through.

Is there any other policies or anything that may be in place that I could check? I am unsure of why I can ping from Texas -> New York but not the other way around.

Any thoughts or suggestions? Any help appreciated! Thanks!



No comments:

Post a Comment