Troubleshooting¶
Quick triage¶
- Is the tunnel up? (SAs / logs)
- Do routes exist both ways? (effective routes, BGP learned)
- Is traffic permitted? (firewall policy hit counts)
- Asymmetric paths? (SNAT/match rules)
Useful commands¶
- Azure:
Test-AzNetworkConnectivity, effective routes - FortiGate:
diag vpn ike,diag debug flow
Common symptoms¶
- DPD failures check NAT-T and timers
- One-way reachability UDR asymmetry / policy