Back to Learning
Fortinet · NSE 4

FortiGate Policy & IPsec VPN

An IPsec tunnel stuck before Phase 1 finishes, with nothing useful in the event log. Read the real IKE negotiation, live, right below.

Interactive simSecurityVPNIPsec

Symptom

Firewall policies, SD-WAN rules and a site-to-site IPsec tunnel between two FortiOS gateways.

Your mission

Inspect, recover, then verify

Format

FortiOS CLI

FortiGate: The Tunnel That Negotiates and Never Comes Up

Investigate before you configure.

Use the CLI evidence to isolate the fault, make the smallest safe correction, then verify the network state changed.

Observe the symptom and link state.

Diagnose by comparing the protocol evidence.

Verify the expected device state and confirm the original symptom is resolved.

Console access: FortiGate HQ

This workspace stacks for portrait phones. Rotate to landscape for the full split-screen console.

Need a hint?

Reveal the root cause when you're ready.

Try the investigation first, then use this as your escape hatch, not a dead end.

Locked

Sign up with your email to open FortiGate Policy & IPsec VPN, free. You get the root cause and the full step-by-step fix.

No spam. The fix lands in your inbox too. Signing up includes 4 guided labs free, tracked against your email. After that, the Learning Pass unlocks every remaining lab.

Lab debrief

Turn the session into a repeatable troubleshooting pattern.

Use this reference after your attempt: first explain the symptom, then verify the evidence, then confirm the repair.

The problem

A site-to-site IPsec tunnel between two FortiGates refuses to come up. Both sides show the tunnel as configured, but Phase 1 never seems to finish.

What you'll practice

  • Configure firewall policies on FortiOS
  • Set up SD-WAN rules across multiple links
  • Build a site-to-site IPsec VPN between two FortiGate gateways
  • Verify phase 1 / phase 2 IPsec negotiation
  • Troubleshoot a tunnel that won't come up

The topology

Two FortiGate gateways, each fronting a small local network, connected over a simulated WAN link, the standard site-to-site topology used to practice IPsec VPN and SD-WAN policy.

Commands to run yourself

The real diagnostic commands for this lab, copy-paste ready. Run these in the same order to reproduce the investigation on your own session.

Read the tunnel's IKE state
diagnose vpn ike gateway list
Compare the Phase 1 proposal
show vpn ipsec phase1-interface
Filter the IKE log to this peer
diagnose vpn ike log-filter name to-branch

Topology diagram

Fact-checked references

The commands and behaviour in this lab were checked against these primary references.

Frequently asked

Do I need two physical FortiGate appliances?

No. Both FortiOS gateways are already provisioned and networked. You configure policy and the VPN tunnel, nothing to rack.

Is this relevant to NSE 4?

Firewall policy, SD-WAN and IPsec VPN are core NSE 4 topics. This lab is scoped directly to that exam.

Ready to run this lab yourself?

No setup, no image sourcing. Book a session or ask for a live demo.