A FortiGate administrator is troubleshooting an IPsec VPN between two FortiGates. The tunnel is established, but traffic is not passing. The administrator runs 'diagnose vpn ike log' and sees the following output: IKE: phase 2 negotiation completed IKE: IPsec SA up What THREE possible causes should the administrator investigate?
Even after an IPsec tunnel reaches Phase 2, traffic is still subject to the firewall policy database on each FortiGate. If no policy with action ACCEPT exists that matches the source/destination subnets and the incoming/outgoing interface (e.g., the IPsec virtual interface), the firewall silently drops the packets. A common misconfiguration is creating a policy for the WAN interface instead of the tunnel interface, or setting the wrong local/remote addresses in the policy.
Why this answer