Site-To-Site vpn connection with fortigate

Pieter Vercruyce 0 Reputation points
2023-06-22T12:23:47.7733333+00:00

We have the following setup with a customer:

  • The customer hosts a Fortigate VPN gateway in Azure.
  • We use standard Azure VPN Site-To-Site connection

Azure portal reports the connection is connected and the customer is able to initiate communication with our side. However, they do not receive any packets back.
I took a packet capture on the tunnel, and as you can see we receive a SYN which we answer with a SYN ACK, but this is never received at the customer.

Then we are stuck in retransmitting the SYN ACK since we never receive an ACK.

Does anyone have an idea where our packets are dropped?

Schermafbeelding 2023-06-22 om 14.19.33

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
{count} votes

1 answer

Sort by: Most helpful
  1. ChaitanyaNaykodi-MSFT 27,661 Reputation points Microsoft Employee Moderator
    2023-06-24T03:02:12.0266667+00:00

    @Pieter Vercruyce

    Thank you for reaching out.

    It will help if you can perform the packet captures on your VPN Gateway as it will help us determine where the packets are getting dropped. You can follow the documentation here to implement the packet capture.

    Please let us know if you have any questions. Thank you!

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.