The VIP that you are attempting to ping, where does this sit? Between the MM or MD's?
In the first instance, confirm if any traffic from either end is traversing the VPN '#show datapath session | include [MM or MD IP].
The check the logs at either end to confirm if you have any configuration issues (e.g are you using cert or PSK for MM/MD auth?).
Has this worked previously?
------------------------------
Craig Syme
------------------------------
Original Message:
Sent: Mar 29, 2021 07:30 AM
From: Aghiles DOUICHER
Subject: MC TO MM communication issue over Fortigate IPsec Tunnel
Hi every one,
I had an issue to connect an Aruba controller deployed (in a branch) to a mobility master (In HQ). the two sites are connected with an a Fortinet IPsec vpn and the mobility controller use this tunnel to connect to the mobility master.
The problem thet the communication dont work and the IPsec tunnel between the MC and MM is not establishing. When i try to ping the MM from the MC, the MM VIP is not reachable but i coud ping the physical adresses.
Best regards
------------------------------
Aghiles DOUICHER
------------------------------