Ipsec tunnel one way reachability
  

Newbie121371 Lv1Posted 2026-Jul-22 14:14

i configured ipsec tunnel between fortifate and sangfor firewall the tunnel is up on both side, but sangfor cannot ping to fortigate ip or any subnet , but fortigate have reachability to sangfor network, i am failed to reach customer support, any help from your side would be appreciated.
Prosi Lv4Posted 2026-Jul-23 12:02
  
Hi, causes to check:

1. Verify Phase 2 Selector (Most Common). Ensure both sides have matching local and remote subnets.

2. Check the Sangfor Security Policy (Local & Remote LAN, ICMP). Also, ensure there are no policies above it that deny traffic.

3. Check the NAT Policy. Traffic entering the IPsec tunnel should not be source NATed.

4. Verify Routing. Ensure Sangfor has a route to the remote subnet through the IPsec tunnel.
Zonger Lv5Posted 2026-Jul-24 06:05
  
If the IPsec tunnel is UP on both FortiGate while Sangfor and FortiGate can reach Sangfor but Sangfor cannot reach FortiGate, the issue is almost always a routing, policy or Phase 2 selector mismatch on the Sangfor side.
George Fady Lv2Posted 2026-Jul-24 16:35
  
please, can you check my last post!