Cloud Managed Networks

 View Only
  • 1.  AOS10 Gateway site to site vpn debug

    Posted Apr 01, 2025 02:42 PM

    Dear Experts, 

    We are trying to establish s2s vpn with fortigate however its not getting up. How we can run the show commands in aos10 gateway to understand better what might be the issue?



    ------------------------------
    iqbal
    ------------------------------


  • 2.  RE: AOS10 Gateway site to site vpn debug

    Posted Apr 01, 2025 05:00 PM
    • Start with verifying that the configuration matches 
    • Review logs; VPN negotiation errors usually provide clear clues.
    • You can try the following commands:
      - show crypto ipsec sa
      - show crypto isakmp sa
      - show log security all

    Enable debugging :




  • 3.  RE: AOS10 Gateway site to site vpn debug

    Posted Apr 02, 2025 06:04 AM

    Ok i will try it

    Meanwhile i am testing s2s vpn in my lab to check, can you also tell me the which logging command gives me detailed debug output of ike and ipsec?



    ------------------------------
    iqbal
    ------------------------------



  • 4.  RE: AOS10 Gateway site to site vpn debug

    Posted Apr 02, 2025 06:23 AM

    Like harriman was mentioning you can use the commands "show crypto ipsec sa" and show crypto isakmp sa" to get the detailed output. At the VPN peer IP to the command to get the detailed output for a specific SA



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------



  • 5.  RE: AOS10 Gateway site to site vpn debug

    Posted Apr 02, 2025 06:30 AM
    Its showing ipsec is up but both sites cannot ping, 






  • 6.  RE: AOS10 Gateway site to site vpn debug

    Posted Apr 02, 2025 07:06 AM
    Edited by willembargeman Apr 02, 2025 10:15 AM

    Did you add some ip subnets to the ipsec tunnel? Or did you use any as source / destination network? If yes, you should at an IP route or use PBR policy



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------