SONICWALL TO FORTIGATE VPN
munaweriqbal Newbie ✭
in SSL VPN
i was using SonicWall to FortiGate site-to-site connectivity. a few days back my isp change the connection PPPoE to DHCP after that both sites are disconnected. can anyone help me in this regards? kindly contact reply.
Category: SSL VPN
Hey! You will be signed out in 60 seconds due to inactivity. Click here to continue using the site.
Inform your ISP provider to open IPSEC ports in your back end ISP modem.
but my FortiGate is working with the same. the only issue with SonicWall.. if IPSEC ports are disabled then how is FortiGate connected?
You said now you are getting DHCP leased IP in WAN interface from ISP, so inform the ISP /you can open the ISP modem, open the IPSEC ports as well as try to disable the NAT Traversal from your Sonicwall Firewall --> VPN Settings and try.
Did you update the VPN tunnel config to match the new ISP information? What is your log saying about the VPN connection? PSK mismatch? Have you done any troubleshooting?
IKE Initiator: Proposed IKE ID mismatch
I would suggest you to check the remote ID on one end of the tunnel has been set incorrectly.
will you please send me the picture for this.. did you understand my issue? my SonicWall was connected with the Fortigate. my ISP change the plan and changed the settings from PPPoE to DHCP from my FortiGate and put the router between ONT and FortiGate. till then my SonicWall is not able to connect to my Fortigate.
AJISHLAL provided you the answer.
I am not familiar with Fortigates, but a quick web search would point you toward the VPN \ IPSec Tunnels page. Edit the tunnel in question and double check the settings, specifically the IKE ID used.
Since the ISP changed you from PPPOE to DHCP, did you receive a new IP address?
We can only guide you as much as we can, you have to do some of the troubleshooting yourself.
You can find out below doc about ike settings.
my issue is not the IPSec dialup tunnel. It's SITE TO SITE connectivity between SonicWall to FortiGate.
sorry, I didn't give detail about link. You have a ike id problem on firewalls. You should change the new isp ip on the ike settings. this document includes ike id settings. therefore I have send for this
I am sorry dear I didn't get you.