1/2
Ipsec tunnel one way reachability

Newbie121371 Lv1Posted 2026-Jul-22 14:14

i configured ipsec tunnel between fortifate and sangfor firewall the tunnel is up on both side, but sangfor cannot ping to fortigate ip or any subnet , but fortigate have reachability to sangfor network, i am failed to reach customer support, any help from your side would be appreciated.

Prosi has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Hi, causes to check:

1. Verify Phase 2 Selector (Most Common). Ensure both sides have matching local and remote subnets.

2. Check the Sangfor Security Policy (Local & Remote LAN, ICMP). Also, ensure there are no policies above it that deny traffic.

3. Check the NAT Policy. Traffic entering the IPsec tunnel should not be source NATed.

4. Verify Routing. Ensure Sangfor has a route to the remote subnet through the IPsec tunnel.
Is this answer helpful?
Korchai Lv2Posted 2026-Jul-27 20:34
  
1. Examine the most widely used Phase 2 Selector. Verify that both sides' distant and local subnets match.

2. Review the Sangfor Security Policy (Local & Remote LAN, ICMP). Verify if there are no laws that forbid driving over it.

3. Look over the NAT Policy. Traffic entering the IPsec tunnel shouldn't be subject to source NATing.

4. Examine the route. Verify Sangfor's IPsec tunnel route to the remote subnet.
Newbie A4 Lv2Posted 2026-Jul-27 17:57
  
The IPsec tunnel is operational on both FortiGate and Sangfor. FortiGate can connect to Sangfor, but Sangfor cannot connect to FortiGate. This is typically caused by a routing, policy, or Phase 2 selection mismatch on the Sangfor end.
AR Lv3Posted 2026-Jul-25 14:51
  
1. Check the most popular Phase 2 Selector. Make sure the local and distant subnets on both sides match.

2. Examine the Sangfor Security Policy (ICMP, Local & Remote LAN). Make sure there are no regulations that prohibit traffic above it as well.

3. Examine the NAT Policy. There should be no source NATing of traffic entering the IPsec tunnel.

4. Check the routing. Make that Sangfor has an IPsec tunnel route to the distant subnet.
George Fady Lv2Posted 2026-Jul-24 16:35
  
please, can you check my last post!
Zonger Lv5Posted 2026-Jul-24 06:05
  
If the IPsec tunnel is UP on both FortiGate while Sangfor and FortiGate can reach Sangfor but Sangfor cannot reach FortiGate, the issue is almost always a routing, policy or Phase 2 selector mismatch on the Sangfor side.

I Can Help:

Change

Moderator on This Board

1
156
3

Started Topics

Followers

Follow

1119
238
101

Started Topics

Followers

Follow

Board Leaders