IPsec tunnel is established but internal resources are unreachable
Confirmed 9/19/2026
Problem
An IPsec VPN tunnel connects successfully, but VPN users cannot access resources on the company’s internal network. Tunnel establishment confirms that negotiation completed; it does not confirm that user traffic has a valid end-to-end path.
Symptoms
The IPsec tunnel shows as connected or UP, while connections from the VPN client or remote subnet to internal destination IP addresses fail.
Environment
FortiGate with an IPsec VPN and Active Directory user-group integration.
Root Cause
In the reported case, the issue was caused by the user-group connection from Active Directory. Similar symptoms can also result from incorrect Phase 2 selectors, missing or inactive routes, firewall-policy mismatches, or an invalid return path.
Solution
- Review the Phase 2 configuration and confirm that it includes the VPN client or remote subnet and the intended internal destination subnet.
- Verify that the FortiGate has an active route for the internal destination through the appropriate IPsec tunnel.
- Check that a firewall policy permits traffic from the IPsec tunnel to the internal network and that its source and destination address objects match the expected traffic.
- Confirm that the internal network has a route back to the VPN client or remote subnet. An incorrect return path can prevent communication even when the tunnel is UP.
- Review the Active Directory user-group connection and correct its configuration or association. This was the resolution in the reported case.
- If the issue remains, trace one specific connection from a VPN client to one internal IP address to determine where the traffic is dropped.
Verification
Confirm that the IPsec tunnel remains established, then test access from a VPN client to a specific internal IP address. Successful bidirectional communication verifies the selectors, route, firewall policy, return path, and user-group handling.
Tags
No tags yet.
Community rating
— / 5 (0)
Discussion (0)
No comments yet.