A FortiGate administrator is configuring a route-based IPsec VPN between two FortiGate devices. After setting up the tunnel and firewall policies, traffic does not flow. The administrator runs 'diagnose vpn tunnel list' and sees the tunnel is up. 'get router info routing-table all' shows routes on both sides. However, pings from the local network to the remote network fail. What is the MOST likely cause?
In a route-based VPN, the policy must be configured with the VPN interface as the destination interface (if traffic flows from internal to VPN) or source interface (if from VPN to internal). Misconfiguration here causes traffic to be dropped.
Why this answer
The tunnel is up and routes are present, indicating Phase 1 and Phase 2 negotiations succeeded. The most likely cause is that the firewall policy allowing traffic to the remote subnet has the source and destination interfaces reversed. In a route-based VPN, the policy must have the incoming interface as the source (e.g., internal) and the outgoing interface as the destination (e.g., the VPN tunnel interface).
Reversing these prevents traffic from being matched, even though the tunnel is established.
Exam trap
The trap here is that candidates assume a tunnel being up and routes present guarantees traffic flow, overlooking that the firewall policy's interface direction must match the traffic flow, not the tunnel's logical direction.
How to eliminate wrong answers
Option A is wrong because an incorrect pre-shared key would prevent Phase 1 from completing, causing the tunnel to show as down, not up. Option C is wrong because the remote FortiGate's static route pointing to the wrong local subnet would cause asymmetric routing or unreachability, but the local side's routes are correct per the scenario; the issue is on the local firewall policy, not the remote route. Option D is wrong because mismatched Phase 2 proposals would cause the tunnel to fail to establish or show as up with no traffic, but 'diagnose vpn tunnel list' would typically show a down or error state, not 'up'.