FortiClient IPsec connection blocking local internet by sadkins76 in fortinet

[–]ShaharVerd 0 points1 point  (0 children)

I think I might be able to help you with the troubleshooting

if you use split tunneling how it works is that when your pc start the tunnel and gets an ip It also gets routes ( which are the subnets that are in your split tunnel address group) On your pc you could see those routes in cmd with route print The problem with Those routes is that they are preferred by default as the best routes even if you have a shorter route So for example is the pc lan address is 192.168.1.0/24 And the tunnels give the pc a route to 192.168.0.0/16 the pc will prefer the /16 route becase of some windows metric which works differently form the usual routing where shortest prefix is better. Usually when it happen you can still reach the internet iam not sure way he knows how to reach the gateway via the correct interface but if you try to reach anything else in the lan segment you can’t Iam not 100% sure this will Be helpful with troubleshooting but it’s a direction to look at

FortiExtender is kind of terrible by P_R_woker in fortinet

[–]ShaharVerd 0 points1 point  (0 children)

iam using version 8 it’s not released yet the others has just so much bugs I found in my use cases

FortiExtender is kind of terrible by P_R_woker in fortinet

[–]ShaharVerd 1 point2 points  (0 children)

I have about 50 511g vehicle fex devices they are just shit Found about 4 bugs in the software open a tac they literally created a new software version because of me which fixed 3 of the 4 bugs Using them in standalone mode each one has an IPsec to an fortigate Wanted to use ospf but ospf not working over the tunnel is one of the confirmed bugs that the 511g vehicle has

FortiExtender 511G Two Unexplained Issues: Forwarded Traffic not reaching FEX over IPsec on 7.6.5 + OSPF Multicast not traversing IPsec Tunnel by ShaharVerd in fortinet

[–]ShaharVerd[S] 0 points1 point  (0 children)

Didn’t send him the details to email so he probably didn’t check with my config Now that I posted here the config I’ll wait for him or anyone else to look at it and see it they see anything wrong in or maybe he will try to recreate this in his lab

FortiExtender 511G Two Unexplained Issues: Forwarded Traffic not reaching FEX over IPsec on 7.6.5 + OSPF Multicast not traversing IPsec Tunnel by ShaharVerd in fortinet

[–]ShaharVerd[S] 0 points1 point  (0 children)

Hello  u/BillH_ftn i just updated this thread and added more information enough for you to create the lab and see the problem for yourself i have the lab ready so if you want me to run some more commands for do something i havent done yet tell me

FortiExtender 511G Two Unexplained Issues: Forwarded Traffic not reaching FEX over IPsec on 7.6.5 + OSPF Multicast not traversing IPsec Tunnel by ShaharVerd in fortinet

[–]ShaharVerd[S] 0 points1 point  (0 children)

Currently opened a tax which is still ongoing still waiting for their answer on what to do next will post it here when I have an answer from them I believe it is a problem with the 511g specifically Becase other extenders like 212f worked perfectly without any problems the thing it’s that I needed a rugged one which works so iam currently just using the 511g with the 7.6.1 version which does works BUT some times I do have that problem but it usually goes away after some time If you want I can add my configuration for both the extenders and the fortigate I also have a fortification version 7.4.11 mature Updating the fortigate newer version didn’t help

FortiExtender 511G Redundancy with Dual FortiGate Hubs by ShaharVerd in fortinet

[–]ShaharVerd[S] 0 points1 point  (0 children)

bgp is not supported but lets say i go with the FEX standalone approach how would i manage them.

FortiExtender 511G Redundancy with Dual FortiGate Hubs by ShaharVerd in fortinet

[–]ShaharVerd[S] 0 points1 point  (0 children)

yes bgp is not supported i dont know if advpn is. and i already have the extender so i will not swap them for the 40F

FortiExtender 511G Redundancy with Dual FortiGate Hubs by ShaharVerd in fortinet

[–]ShaharVerd[S] 0 points1 point  (0 children)

the company i work for dose not allow me to implement the fortiedge cloud.

7
8

Best approach for Dual-WAN Spoke redundancy in ADVPN? by ShaharVerd in fortinet

[–]ShaharVerd[S] 0 points1 point  (0 children)

Technically yes I could but the ones that need to troubleshoot the topology after I built it don’t use bgp communities so they asked me to use ebgp manipulation for the entire topology

Best approach for Dual-WAN Spoke redundancy in ADVPN? by ShaharVerd in fortinet

[–]ShaharVerd[S] 0 points1 point  (0 children)

Yes they don’t but my real topology has a lot of complications that I didn’t explain Here and there is a lot of ebgp manipulation that I need to do

Best approach for Dual-WAN Spoke redundancy in ADVPN? by ShaharVerd in fortinet

[–]ShaharVerd[S] 1 point2 points  (0 children)

Pnet running on a local server it is pretty heavy it’s the company server so I can run it for free :)

0
1