Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Bullhead
New Contributor

Site-2-Site VPN with VoIP

Hi Everyone,

 

I apologise in advance if this request for help is in the wrong section.

 

I've taken on a new customer that has 2 sites with a Fortigate 60E Firewall at each location providing Site-2-Site VPN for Data. This is working flawlessly and they've never had any issues. They recently purchased a VoIP system (prior to being a customer) which is completely separate and runs on its own set of Switches. (each desk has 2 network drops. 1 for Data & 1 for Voice). The VoIP system has been configured with 192.168.10.x with VLAN 100 on those switches. Again, no issue with the phone system at Head Office.

 

They now want to add IP Phones in their Branch Office and I'm not 100% sure what is the best way to achieve this. Fortinet & Fortigate are new to me so I'm learning as I go.

 

My first thought was to setup an interface on the Fortigate at the HO as a Voice Gateway (192.168.10.254) and attach it to one of the VoIP Switches. Then Configure the necessary DHCP etc that this is the GW. This gets to the traffic to the Firewall (I believe). I've then got to some how allow this subnet to use the existing Site-2-Site VPN Tunnel and I assume I have to add this Subnet to it. Also, I suspect there must be some sort of QoS that I can set/maybe?!?

 

At the BO I would do the same but create a Voice Subnet of 192.168.11.x with a GW of 192.168.11.254 which connects to a free port on the Fortigate at the BO. Same setup, allow 192.168.11 to use the existing Site-2-Site VPN. I'll have to configure the switch at the BO with VLAN 100 with DHCP I suspect for the phones, Data is in the default VLAN at the moment and I'm going to use a single switch for both Voice and Data with QoS.

 

Or...

 

Can you use the same subnet in both the HO & BO ?!?!? I don't see how this would route successfully but I did read somewhere that certain Cisco units or Sonic Firewall units can do this. Not sure how this would work but maybe it's possible and the correct way to go.

 

Or...

 

Would Static IP's (192.168.10.x) work for the Ip Phones in the BO as long as the the BO could route this subnet back to the HO ?

 

I've read a lots of comments from several different forums regarding this exact requirement of setting up VoIP at a BO over VPN but there has never been a clear indication of the best solution to use, and the more I think about it the more elaborate and stupid my ideas get!!! 

 

I know there are many ways this can be achieved depending on setup and equipment, but I'm not familiar with how Fortigate would recommend to achieve this.

 

I'm hoping the xperts here can give me a Dummies walkthrough on how I can Achieve this.

 

Appreciate the help. 

 

So here is the run down of subnets 

 

DATA Subnets

HO - 192.168.100.x

 GW - 192.168.100.254

BO - 192.168.101.x

 GW - 192.168.101.254

 

Voice Subnets

HO - 192.168.10.x

 GW - 192.168.10.254 (Possibly)

BO - 192.168.11.x (Possibly)

 GW - 192.168.11.254 (Possibly)

 

1 REPLY 1
Bullhead
New Contributor

Can anyone help?
Labels
Top Kudoed Authors