FortiGate Policy & IPsec VPN
An IPsec tunnel stuck before Phase 1 finishes, with nothing useful in the event log. Read the real IKE negotiation, live, right below.
Symptom
Firewall policies, SD-WAN rules and a site-to-site IPsec tunnel between two FortiOS gateways.
Your mission
Inspect, recover, then verify
Format
FortiOS CLI
Investigate before you configure.
Use the CLI evidence to isolate the fault, make the smallest safe correction, then verify the network state changed.
Observe the symptom and link state.
Diagnose by comparing the protocol evidence.
Verify the expected device state and confirm the original symptom is resolved.
Console access: FortiGate HQ
This workspace stacks for portrait phones. Rotate to landscape for the full split-screen console.
Need a hint?
Reveal the root cause when you're ready.
Try the investigation first, then use this as your escape hatch, not a dead end.
Lab debrief
Turn the session into a repeatable troubleshooting pattern.
Use this reference after your attempt: first explain the symptom, then verify the evidence, then confirm the repair.
The problem
A site-to-site IPsec tunnel between two FortiGates refuses to come up. Both sides show the tunnel as configured, but Phase 1 never seems to finish.
What you'll practice
- Configure firewall policies on FortiOS
- Set up SD-WAN rules across multiple links
- Build a site-to-site IPsec VPN between two FortiGate gateways
- Verify phase 1 / phase 2 IPsec negotiation
- Troubleshoot a tunnel that won't come up
The topology
Two FortiGate gateways, each fronting a small local network, connected over a simulated WAN link, the standard site-to-site topology used to practice IPsec VPN and SD-WAN policy.
Commands to run yourself
The real diagnostic commands for this lab, copy-paste ready. Run these in the same order to reproduce the investigation on your own session.
diagnose vpn ike gateway listshow vpn ipsec phase1-interfacediagnose vpn ike log-filter name to-branchTopology diagram
Fact-checked references
The commands and behaviour in this lab were checked against these primary references.
Frequently asked
Do I need two physical FortiGate appliances?
No. Both FortiOS gateways are already provisioned and networked. You configure policy and the VPN tunnel, nothing to rack.
Is this relevant to NSE 4?
Firewall policy, SD-WAN and IPsec VPN are core NSE 4 topics. This lab is scoped directly to that exam.
Ready to run this lab yourself?
No setup, no image sourcing. Book a session or ask for a live demo.