Thanks to all for your messages. @ lescudero :
Thanks for your help, but according to me it will not change the routes issue (two routes with the same destination, as I can only route the mapped network). @ Toshi :
What is your objective setting up two VPNs with two locations where they have the same subnet?
Do you really need to reach each devices at the customer locations from your end, or they need to reach common resources at your location X?
We need to reach each devices at the customer locations from our end.
Obviously you can't have the remote subnet 10.93.1.0/24 exposed in your local FGT. How do you or FGT differenciate a device 10.93.1.10 at location Y from another 10.93.1.10 device at location Z to send packets into the tunnel?
You need to use VIPs to have different subnet/IPs to specify each device that has the same local IP.
That's done, I use one VIP for each VPN :config firewall vipedit "NAT_DEST_Y_LAN"set extip 10.129.7.1-10.129.7.254set mappedip "10.93.1.1-10.93.1.254"config firewall vipedit "NAT_DEST_Z_LAN"set extip 10.129.100.1-10.129.100.254set mappedip "10.93.1.1-10.93.1.254"
But what about the routes ? Routing the VIP External network (i.e. 10.129.x.0/24) into the VPN tunnel does not work according to my tests. If I have to route the mapped network (i.e. 10.93.1.0/24), the two route will have the same destination. That's the problem.
But if only customer side needs to reach your common resources, the remote FGTs need just SNAT.
Unfortunately we need to reach each devices at the customer locations from our end. @ ericli_FTNT
Not sure to understand your point.
1. The VIP are applied to the incoming interface ("VPN_INTERCO-IN"). According to the packet flow diagram, the destination NAT is done before the routing. So I should be able to use Externat network (i.e. 10.129.x.0/24) in my routes - but only routes using mapped network (i.e. 10.93.1.0/24) works.
2. I tried to apply the VIP to the tunnel interfaces. I can do that, but after I can not chosse the VIP as destination in my policy !
post edited by Fabien_34 - 2018/06/07 10:59:31