01-29-2018 11:41 PM - edited 03-12-2019 04:58 AM
Hi,
My VPN site-to-site between Cisco ASA5525 (Site1) and Fortigate 60D(Site2) established, all servers, clients of 2 sites can connect eachother without any error.
the problem is: from fortigate, i could not setup LDAP authentication connection with a server located on Site1, error: Could not contact with LDAP server...
I tried to ping LDAP server and clients on Site1, failed
From ASA5525 on Site1, I also could not ping fortigate60D or clients on Site2,
Anyone can help would be appreciated.
Many thanks.
01-30-2018 01:52 AM
Hi
Lets try to help at least on the Cisco part. Do you have sysopt enabled on ASA or are you using VPN filter?
I assuming that you probably need to permit something on this traffic.
When you say from ASA you can not ping host on Site 2, this is the expected behavior. The traffic to be tunneled is the traffic behind firewall not the traffic generated on firewall.
Make sure you have all the required network on you policies.
-If I helped you somehow, please, rate it as useful.-
01-30-2018 06:22 PM - edited 01-30-2018 06:22 PM
Hi,
This is my sysopt result:
no sysopt connection timewait
sysopt connection tcpmss 0
sysopt connection tcpmss minimum 0
sysopt connection permit-vpn
no sysopt connection reclassify-vpn
no sysopt connection preserve-vpn-flows
no sysopt radius ignore-secret
no sysopt noproxyarp outside
no sysopt noproxyarp inside
sysopt noproxyarp management
no sysopt noproxyarp Viettel
no sysopt noproxyarp ViettelFTTH
I dont know if any thing wrong, All interfaces disabled except inside and outside.
Thanks.
01-30-2018 04:00 AM
Hello,
On the FortiGate which type of VPN configured means as S2S or Dial-up. My suggestion to configure the correct policy on the fortiGtae firewall.
If VPN seems up but there is no data on VPN tunnel then please verify VPN tunnel on both end and routing table on FortiGate.
Make sure, you are not missing any ACL on ASA and policy on FortiGate.
Regards,
Deepak Kumar
01-30-2018 06:08 PM
Hi,
My VPN is site to site, not dial-up. All working well, except from firewalls.
Quite strange.
Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide