Chapter 11 IPsec VPN for FortiOS 5.0 : GRE over IPsec (Cisco VPN) : Troubleshooting : Quick checks
  
Quick checks
Here is a list of common problems and what to verify.
Problem
What to check
No communication with remote network.
Use the execute ping command to ping the Cisco device public interface.
Use the FortiGate VPN Monitor page to see whether the IPsec tunnel is up or can be brought up.
IPsec tunnel does not come up.
Check the logs to determine whether the failure is in Phase 1 or Phase 2.
Check that the encryption and authentication settings match those on the Cisco device.
Check the encapsulation setting: tunnel-mode or transport-mode. Both devices must use the same mode.
Tunnel connects, but there is no communication.
Check the security policies. See “Configuring security policies”.
Check routing. See “Configuring routing”.